Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RIESGO
abrir ↗Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RIESGO
abrir ↗Referência
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RIESGO
abrir ↗Referência✓ VexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RIESGO
abrir ↗Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RIESGO
abrir ↗Referência✓ VexDay Proof
Tuned Studios Templates - Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RIESGO
abrir ↗Referência
CVE-2012-6044
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
23RIESGO
abrir ↗Referência
CVE-2018-7176
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u
23RIESGO
abrir ↗Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RIESGO
abrir ↗Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RIESGO
abrir ↗Referência
CVE-2017-9415
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target u
23RIESGO
abrir ↗Referência
CVE-2009-4927
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cook
23RIESGO
abrir ↗Referência
CVE-2026-14547
Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
33RIESGO
abrir ↗Referência✓ VexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
CFAGCMS 1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 all
23RIESGO
abrir ↗Referência
CVE-2010-1720
SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote atta
23RIESGO
abrir ↗Referência
CVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
43RIESGO
abrir ↗Referência✓ VexDay Proof
basebuilder 2.0.1 - 'main.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2013-0249
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7
28RIESGO
abrir ↗Referência
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RIESGO
abrir ↗Referência
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RIESGO
abrir ↗Referência
CVE-2012-1049
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.