Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.573 exploits
Referência✓ VexDay Proof
Anon Proxy Server 0.1000 - Remote Command Execution
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Referência
CVE-2009-4627
Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Rianxosencabos CMS 0.9 - Insecure Cookie Handling
Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the us
23RIESGO
abrir ↗Referência
CVE-2017-15972
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php
23RIESGO
abrir ↗Referência
CVE-2017-15972
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php
23RIESGO
abrir ↗Referência
CVE-2006-4611
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2020-14073
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer (Windows Vista) - XML Parsing Buffer Overflow
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RIESGO
abrir ↗Referência
CVE-2021-25679
The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. T
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netref 4 - 'cat_for_aff.php' Source Code Disclosure
Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Referência
CVE-2010-1652
Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attac
23RIESGO
abrir ↗Referência
CVE-2010-1652
Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attac
23RIESGO
abrir ↗Referência
CVE-2018-10309
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hot or Not Clone by Jnshosts.com - Database Backup Dump
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
MODx CMS 0.9.6.2 - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Safari - 'ARGUMENTS' Array Integer Overflow HeapSpray (PoC)
Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cau
23RIESGO
abrir ↗Referência✓ VexDay Proof
blogplus 1.0 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary loc
23RIESGO
abrir ↗Referência
CVE-2014-4717
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordP
23RIESGO
abrir ↗Referência
CVE-2010-1946
Multiple PHP remote file inclusion vulnerabilities in openMairie Openregistrecil 1.02, when register_globals is enabled,
23RIESGO
abrir ↗Referência
CVE-2026-15375
Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-15188
manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control
33RIESGO
abrir ↗Referência
CVE-2026-11875
WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery
33RIESGO
abrir ↗Referência
CVE-2026-15134
CodeAstro Simple Online Leave Management System index.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and
23RIESGO
abrir ↗Referência
CVE-2010-4771
SQL injection vulnerability to viewforum.php in S-CMS 2.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2026-58473
Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings
48RIESGO
abrir ↗Referência
CVE-2026-23698
Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload
41RIESGO
abrir ↗Referência★ 8
CVE-2026-57851
MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers
41RIESGO
abrir ↗Referência
CVE-2026-4375
DoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.