Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8773Nuclei 4340Metasploit 3485✓ solo verificadosrecientespopularesriesgo
22.657 exploits
Referência✓ VexDay Proof
phpMySms 2.0 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
BXCP 0.3.0.4 - 'where' SQL Injection
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Powies MatchMaker 4.05 - 'matchdetail.php' SQL Injection
SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Invision Power Board 2.1 < 2.1.6 - SQL Injection (1)
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Repository - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2026-19344
code-projects Task Management System comment_count_user.php sql injection
33RIESGO
abrir ↗Referência
CVE-2012-5334
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência
CVE-2016-1885
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RIESGO
abrir ↗Referência
CVE-2016-1885
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RIESGO
abrir ↗Referência
CVE-2026-10220
NousResearch hermes-agent skills_tool.py skill_view injection
33RIESGO
abrir ↗Referência
CVE-2026-8113
8421bit MiniClaw executeSkillScript kernel.ts isPathInside path traversal
33RIESGO
abrir ↗Referência
CVE-2026-8112
8421bit MiniClaw kernel.ts executeCognitivePulse os command injection
33RIESGO
abrir ↗Referência
CVE-2014-10019
Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Ga
23RIESGO
abrir ↗Referência✓ VexDay Proof
Friendly Technologies - 'fwRemoteCfg.dll' ActiveX Command Execution
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot
23RIESGO
abrir ↗Referência
CVE-2017-9150
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RIESGO
abrir ↗Referência
CVE-2022-50691
MiniDVBLinux 5.4 Remote Root Command Execution via commands.sh
48RIESGO
abrir ↗Referência
CVE-2015-4119
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac
23RIESGO
abrir ↗Referência
CVE-2015-4119
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac
23RIESGO
abrir ↗Referência✓ VexDay Proof
iG Calendar 1.0 - 'user.php?id' SQL Injection
SQL injection vulnerability in user.php in iGeneric iG Calendar 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2020-2038
PAN-OS: OS command injection vulnerability in the management web interface
78RIESGO
abrir ↗Referência
CVE-2026-17017
CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation
41RIESGO
abrir ↗Referência✓ VexDay Proof
FlexBB 0.5.5 - '/inc/start.php?_COOKIE' SQL Bypass
SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Okul Web Otomasyon Sistemi 4.0.1 - SQL Injection
SQL injection vulnerability in etkinlikbak.asp in Okul Web Otomasyon Sistemi 4.0.1 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeBSD mcweject 0.9 'Eject' - Local Buffer Overflow / Local Privilege Escalation
Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to
23RIESGO
abrir ↗Referência✓ VexDay Proof
wolioCMS - Authentication Bypass / SQL Injection
Multiple SQL injection vulnerabilities in wolioCMS allow remote attackers to execute arbitrary SQL commands via (1) the
23RIESGO
abrir ↗Referência
CVE-2009-4567
Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated u
23RIESGO
abrir ↗Referência
CVE-2009-4567
Multiple cross-site scripting (XSS) vulnerabilities in editprofile.php in Viscacha 0.8 Gold allow remote authenticated u
23RIESGO
abrir ↗Referência
CVE-2008-5689
tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (pa
23RIESGO
abrir ↗Referência
CVE-2010-2609
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to exe
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.