Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2022-50954
WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion
33RIESGO
abrir ↗Referência
CVE-2022-50948
Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting
33RIESGO
abrir ↗Referência
CVE-2022-50947
WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS
33RIESGO
abrir ↗Referência
CVE-2017-15992
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
23RIESGO
abrir ↗Referência
CVE-2017-15993
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
23RIESGO
abrir ↗Referência
CVE-2017-16001
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently su
23RIESGO
abrir ↗Referência
CVE-2026-8244
Industrial Application Software IAS Canias ERP Login RMI improper authentication
33RIESGO
abrir ↗Referência
CVE-2026-8242
Industrial Application Software IAS Canias ERP Login RMI doAction response discrepancy
33RIESGO
abrir ↗Referência
CVE-2026-8241
Industrial Application Software IAS Canias ERP RMI iasGetServerInfoEvent improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-8235
8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection
33RIESGO
abrir ↗Referência
CVE-2026-8226
Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of service
33RIESGO
abrir ↗Referência
CVE-2026-8225
Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of service
33RIESGO
abrir ↗Referência
CVE-2026-8209
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction
33RIESGO
abrir ↗Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authent
23RIESGO
abrir ↗Referência
CVE-2016-1721
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o
23RIESGO
abrir ↗Referência
CVE-2026-17433
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-14291
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
41RIESGO
abrir ↗Referência✓ VexDay Proof
OmniWeb 5.5.1 - JavaScript alert() Remote Format String (PoC)
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.