Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.133exploits catalogados
35.369CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.232GitHub PoC 14.112VulnCheck XDB 8607Nuclei 4257Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.166 exploits
Referência
CVE-2016-5309
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir ↗Referência
CVE-2010-1925
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2026-11528
Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow
41RIESGO
abrir ↗Referência✓ VexDay Proof
CNStats 2.9 - 'who_r.php?bj' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗Referência
CVE-2009-4796
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flip 3.0 - Remote Admin Creation
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un
23RIESGO
abrir ↗Referência
CVE-2016-5312
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au
35RIESGO
abrir ↗Referência
CVE-2010-4865
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
UploadImage/UploadScript 1.0 - Remote Change Admin Password
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Verlihub Control Panel 1.7.x - Local File Inclusion
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chipmunk Blog - (Authentication Bypass) Add Admin
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.p
23RIESGO
abrir ↗Referência✓ VexDay Proof
Syntax Desktop 2.7 - 'synTarget' Local File Inclusion
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to inclu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Catviz 0.4.0 beta1 - Local File Inclusion / Cross-Site Scripting
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar
23RIESGO
abrir ↗Referência
CVE-2018-17588
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RIESGO
abrir ↗Referência
CVE-2018-17588
AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RIESGO
abrir ↗Referência
CVE-2010-0680
Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗Referência
CVE-2009-4231
Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to includ
23RIESGO
abrir ↗Referência
CVE-2016-4337
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2016-4337
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2015-1424
Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentic
23RIESGO
abrir ↗Referência
CVE-2015-1424
Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentic
23RIESGO
abrir ↗Referência
CVE-2021-24444
TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir ↗Referência
CVE-2018-9183
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RIESGO
abrir ↗Referência
CVE-2009-4739
PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência
CVE-2017-9516
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
23RIESGO
abrir ↗Referência
CVE-2017-9516
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-shop 0.70 - Remote File Deletion
Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.