Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.051exploits catalogados
35.924CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.387VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2015-4039
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent
23RIESGO
abrir ↗Referência
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência
CVE-2014-4977
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir ↗Referência
CVE-2014-4977
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir ↗Referência
CVE-2012-1008
OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SI
28RIESGO
abrir ↗Referência
Sphider Search Engine - Multiple Vulnerabilities
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
28RIESGO
abrir ↗Referência
CVE-2014-5115
Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname
23RIESGO
abrir ↗Referência
CVE-2010-0249
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and S
100RIESGO
abrir ↗Referência
CVE-2012-1208
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other
23RIESGO
abrir ↗Referência
CVE-2012-1213
Cross-site scripting (XSS) vulnerability in zimbra/h/calendar in Zimbra Web Client in Zimbra Collaboration Suite (ZCS) 6
23RIESGO
abrir ↗Referência
CVE-2012-1217
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência
CVE-2026-19246
HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-19230
SourceCodester Photo Share Website Comment Input Box ajax.php save_upload cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-19207
PHPGurukul Company Visitor Management System manage-newvisitors.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-15148
WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR
33RIESGO
abrir ↗Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir ↗Referência
CVE-2010-0467
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RIESGO
abrir ↗Referência
CVE-2012-1979
Cross-site scripting (XSS) vulnerability in starnet/index.php in SyndeoCMS 3.0.01 and earlier allows remote authenticate
23RIESGO
abrir ↗Referência
CVE-2012-2095
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configur
23RIESGO
abrir ↗Referência
CVE-2012-2110
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before
35RIESGO
abrir ↗Referência
CVE-2012-2206
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users
23RIESGO
abrir ↗Referência
CVE-2021-33045
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir ↗Referência★ 52
Scanner for CVE-2024-4040
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗Referência
CVE-2015-8425
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Referência
CVE-2012-2396
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and applicati
23RIESGO
abrir ↗Referência
CVE-2015-8770
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RIESGO
abrir ↗Referência
CVE-2010-0607
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.