Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir ↗Referência
CVE-2017-15973
Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RIESGO
abrir ↗Referência✓ VexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Nitrotech 0.0.3a - Remote Code Execution
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action
23RIESGO
abrir ↗Referência✓ VexDay Proof
SCart 2.0 - 'page' Remote Code Execution
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2006-7127
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência
CVE-2026-8264
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
33RIESGO
abrir ↗Referência
CVE-2026-8263
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
33RIESGO
abrir ↗Referência
CVE-2026-8250
Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of service
33RIESGO
abrir ↗Referência
CVE-2026-8249
Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of service
33RIESGO
abrir ↗Referência
CVE-2021-47930
Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
41RIESGO
abrir ↗Referência
CVE-2014-5144
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (2)
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - '.png' IHDR Block Denial of Service (PoC) (3)
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a
28RIESGO
abrir ↗Referência
CVE-2015-8429
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Referência
CVE-2015-8430
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.