Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.008exploits catalogados
35.919CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.377VulnCheck XDB 8722Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2013-3532
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote
23RIESGO
abrir ↗Referência
CVE-2013-3532
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote
23RIESGO
abrir ↗Referência
CVE-2013-3537
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2026-9627
UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow
41RIESGO
abrir ↗Referência✓ VexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RIESGO
abrir ↗Referência✓ VexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RIESGO
abrir ↗Referência
CVE-2011-3496
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell me
28RIESGO
abrir ↗Referência
CVE-2011-3833
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RIESGO
abrir ↗Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗Referência
CVE-2021-42013
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗Referência
CVE-2026-9575
itsourcecode Student Transcript Processing System index.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9574
itsourcecode Student Transcript Processing System trans.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9573
itsourcecode Student Transcript Processing System index.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7293
SourceCodester Pizzafy Ecommerce System ajax.php delete_category sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RIESGO
abrir ↗Referência
CVE-2015-1130
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir ↗Referência
CVE-2009-4761
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir ↗Referência
CVE-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗Referência
CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir ↗Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RIESGO
abrir ↗Referência
CVE-2011-4800
Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and wri
23RIESGO
abrir ↗Referência
CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Referência
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RIESGO
abrir ↗Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência✓ VexDay Proof
DB Top Sites 1.0 - 'index.php?u' Local File Inclusion
Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack
23RIESGO
abrir ↗Referência
CVE-2011-4812
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.