Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
CVE-2017-8488
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir ↗Referência
CVE-2017-8489
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir ↗Referência
CVE-2017-8491
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir ↗Referência
CVE-2017-8492
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir ↗Referência
CVE-2017-8536
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir ↗Referência
CVE-2017-8537
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir ↗Referência
CVE-2008-6779
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência
CVE-2017-8849
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount hel
23RIESGO
abrir ↗Referência✓ VexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência
CVE-2026-63098
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
33RIESGO
abrir ↗Referência✓ VexDay Proof
ThePortal 2.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência
CVE-2017-8926
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
23RIESGO
abrir ↗Referência
CVE-2017-9101
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir ↗Referência
CVE-2017-9101
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir ↗Referência
CVE-2017-9124
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NU
23RIESGO
abrir ↗Referência
CVE-2017-9248
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir ↗Referência
CVE-2010-4502
Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of
23RIESGO
abrir ↗Referência
CVE-2010-4566
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and
43RIESGO
abrir ↗Referência
CVE-2017-9769
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RIESGO
abrir ↗Referência
CVE-2010-4598
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary f
28RIESGO
abrir ↗Referência
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗Referência
CVE-2026-7750
Totolink N300RH POST Request cstecgi.cgi setMacFilterRules buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7749
Totolink N300RH POST Request cstecgi.cgi setWanConfig buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7748
Totolink N300RH POST Request cstecgi.cgi setUpgradeFW buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7747
Totolink N300RH Parameter cstecgi.cgi loginauth buffer overflow
48RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RIESGO
abrir ↗Referência
CVE-2010-4609
SQL injection vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.