Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência✓ VexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir ↗Referência
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RIESGO
abrir ↗Referência
CVE-2019-25743
WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting
33RIESGO
abrir ↗Referência
CVE-2019-25738
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
48RIESGO
abrir ↗Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-10275
OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
28RIESGO
abrir ↗Referência
CVE-2026-10265
itsourcecode Content Management System edit_topic.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10235
CodeAstro Ingredients Stock Management System stock_manager.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-10233
Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds
33RIESGO
abrir ↗Referência
CVE-2024-14044
Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow
33RIESGO
abrir ↗Referência
CVE-2024-14043
Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2019-13235
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RIESGO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Referência
CVE-2024-14042
Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow
33RIESGO
abrir ↗Referência
CVE-2022-50997
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp
41RIESGO
abrir ↗Referência
CVE-2016-20097
Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad
41RIESGO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.