Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8703Nuclei 4314Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.492 exploits
Referência
CVE-2026-12273
Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
33RIESGO
abrir ↗Referência
CVE-2026-12271
Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-15514
Metasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência
CVE-2017-17600
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RIESGO
abrir ↗Referência
CVE-2017-17600
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
wanewsletter 2.1.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to e
35RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module icontent 1.0/4.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS a
35RIESGO
abrir ↗Referência
CVE-2015-2426
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir ↗Referência
CVE-2020-37252
Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência
CVE-2016-20091
Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência
CVE-2016-20090
Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service Path
41RIESGO
abrir ↗Referência
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir ↗Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
Particle Gallery 1.0.1 - SQL Injection
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RIESGO
abrir ↗Referência
CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir ↗Referência✓ VexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RIESGO
abrir ↗Referência
CVE-2026-18927
imranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-15360
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
48RIESGO
abrir ↗Referência
CVE-2026-15210
Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
48RIESGO
abrir ↗Referência
CVE-2026-15230
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
41RIESGO
abrir ↗Referência
CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.