Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2026-8781
omec-project amf handler.go RANConfiguration null pointer dereference
33RIESGO
abrir ↗Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir ↗Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RIESGO
abrir ↗Referência
CVE-2026-45233
HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave
41RIESGO
abrir ↗Referência
CVE-2019-25763
WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass
48RIESGO
abrir ↗Referência
CVE-2019-25748
Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels
41RIESGO
abrir ↗Referência
CVE-2017-20280
Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
41RIESGO
abrir ↗Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir ↗Referência
CVE-2019-12477
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RIESGO
abrir ↗Referência
CVE-2019-12725
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗Referência
Vim < 8.1.1365 / Neovim < 0.3.6 - Arbitrary Code Execution
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir ↗Referência✓ VexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir ↗Referência
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
28RIESGO
abrir ↗Referência
CVE-2019-25743
WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting
33RIESGO
abrir ↗Referência
CVE-2019-25738
WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change
48RIESGO
abrir ↗Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.