Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.573 exploits
Referência✓ VexDay Proof
i.Scribe SMTP Client 2.00b - 'wscanf' Remote Format String (PoC)
Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to c
23RIESGO
abrir ↗Referência✓ VexDay Proof
MPLAB IDE 8.30 - '.mcp' Universal Overwrite (SEH)
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência
CVE-2010-1174
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RIESGO
abrir ↗Referência
CVE-2021-42325
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RIESGO
abrir ↗Referência
CVE-2010-1296
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RIESGO
abrir ↗Referência
CVE-2017-8490
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir ↗Referência
CVE-2026-18615
GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection
48RIESGO
abrir ↗Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir ↗Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir ↗Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RIESGO
abrir ↗Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RIESGO
abrir ↗Referência
CVE-2013-4092
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent att
23RIESGO
abrir ↗Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RIESGO
abrir ↗Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RIESGO
abrir ↗Referência
CVE-2014-2559
Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPre
23RIESGO
abrir ↗Referência
CVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component beamospetition - SQL Injection
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2021-47964
Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager
41RIESGO
abrir ↗Referência
CVE-2014-9412
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foxmail 5.0 - 'PunyLib.dll' Remote Stack Overflow
Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
East Wind Software - 'advdaudio.ocx 1.5.1.1' Local Buffer Overflow
Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
March Networks DVR 3204 - Logfile Information Disclosure
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RIESGO
abrir ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RIESGO
abrir ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RIESGO
abrir ↗Referência
CVE-2017-11333
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência
CVE-2014-2598
Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.