Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência✓ VexDay Proof
Soulseek 157 NS x/156.x - Remote Distributed Search Code Execution
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RIESGO
abrir ↗Referência
CVE-2023-38035
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an
100RIESGO
abrir ↗Referência
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗Referência✓ VexDay Proof
Winamp 5.55 - MAKI Script Universal Overwrite (SEH)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir ↗Referência✓ VexDay Proof
phpBugTracker 1.0.3 - Authentication Bypass
SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyForum 1.3 - Authentication Bypass
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2009-2309
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência
CVE-2026-7290
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
33RIESGO
abrir ↗Referência
CVE-2022-35405
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RIESGO
abrir ↗Referência
CVE-2009-4785
SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute a
23RIESGO
abrir ↗Referência
CVE-2026-7283
SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7282
SourceCodester Pharmacy Sales and Inventory System ajax.php delete_expired sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7281
SourceCodester Pharmacy Sales and Inventory System index.php supplier cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7272
WilliamCloudQi matlab-mcp-server MCP index.ts execute_matlab_code path traversal
33RIESGO
abrir ↗Referência
CVE-2026-7271
DV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversal
33RIESGO
abrir ↗Referência
CVE-2026-7269
SourceCodester Pharmacy Sales and Inventory System index.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7268
SourceCodester Pizzafy Ecommerce System ajax.php save_category sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7267
SourceCodester Pizzafy Ecommerce System view_prod.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7266
SourceCodester Pizzafy Ecommerce System ajax.php save_order sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7265
SourceCodester Pizzafy Ecommerce System index.php category sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7264
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7248
D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
48RIESGO
abrir ↗Referência
CVE-2026-7247
D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-7244
Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7243
Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2025-10539
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.