Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência✓ VexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RIESGO
abrir ↗Referência
CVE-2026-6011
OpenClaw assertPublicHostname web-fetch.ts server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-6003
code-projects Simple IT Discussion Forum user.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2018-25310
VideoFlow Digital Video Protection DVP 2.10 - Authenticated Remote Code Execution
33RIESGO
abrir ↗Referência
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir ↗Referência
CVE-2023-54362
Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword
33RIESGO
abrir ↗Referência
CVE-2023-54361
Joomla iProperty Real Estate 4.1.1 Reflected XSS via filter_keyword
33RIESGO
abrir ↗Referência
CVE-2018-25318
Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change
48RIESGO
abrir ↗Referência
CVE-2018-25317
Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change
48RIESGO
abrir ↗Referência
CVE-2018-25315
Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name
41RIESGO
abrir ↗Referência
CVE-2018-25314
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow
41RIESGO
abrir ↗Referência
CVE-2018-25313
SysGauge 4.5.18 Local Denial of Service via Proxy Configuration
33RIESGO
abrir ↗Referência
CVE-2018-25304
Free Download Manager 2.0 Build 417 Local Buffer Overflow SEH
41RIESGO
abrir ↗Referência
CVE-2018-17587
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RIESGO
abrir ↗Referência
CVE-2018-17587
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
23RIESGO
abrir ↗Referência
CVE-2026-5453
Rico só vantagem pra investir App br.com.rico.mobile SegmentSettingsModule.java hard-coded key
33RIESGO
abrir ↗Referência
CVE-2026-5452
UCC CampusConnect App campusconnect.ucc BuildConfig.java hard-coded key
33RIESGO
abrir ↗Referência
CVE-2026-5420
Shinrays Games Goods Triple App cats.goods.sort.sorting.games jRwTX.java hard-coded key
28RIESGO
abrir ↗Referência
CVE-2026-5417
Dataease SQLbot Elasticsearch es_engine.py get_es_data_by_http server-side request forgery
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.