Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência✓ VexDay Proof
openPHPNuke 2.3.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência
CVE-2023-36348
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RIESGO
abrir ↗Referência✓ VexDay Proof
Synactis All_IN_THE_BOX ActiveX 3.0 - Null Byte File Overwrite
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX
23RIESGO
abrir ↗Referência✓ VexDay Proof
DynamicPAD 1.02.18 - 'HomeDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência
CVE-2019-6214
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RIESGO
abrir ↗Referência
CVE-2010-1308
Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read a
43RIESGO
abrir ↗Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Referência
CVE-2018-6941
A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2007-0843
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Visit Counter 0.4 - 'datespan' SQL Injection
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência
CVE-2010-1315
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RIESGO
abrir ↗Referência
CVE-2019-12905
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenDock Easy Blog 1.4 - 'doc_directory' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Tizag Countdown Creator 3 - Insecure Upload
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência
CVE-2015-1830
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir ↗Referência✓ VexDay Proof
ReVou Twitter Clone - Arbitrary File Upload
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows
23RIESGO
abrir ↗Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir ↗Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir ↗Referência
CVE-2017-14266
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RIESGO
abrir ↗Referência
CVE-2014-9581
Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read
23RIESGO
abrir ↗Referência
CVE-2014-6070
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RIESGO
abrir ↗Referência
CVE-2010-1335
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RIESGO
abrir ↗Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir ↗Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir ↗Referência
CVE-2018-0969
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir ↗Referência
CVE-2026-9583
SourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure
33RIESGO
abrir ↗Referência
CVE-2008-7008
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a d
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.