Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.329exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.482VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
Joomla JCE_2.9.15 - Remote Code Execution
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗Exploit-DB
webpack_devserver 5.2.5 - CSRF
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
33RIESGO
abrir ↗Exploit-DB
D-Link DNS_340L - OS Command Injection
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir ↗Exploit-DB
NanaZip 6.5 - DoS
NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size
28RIESGO
abrir ↗Exploit-DB
WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload
Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload
68RIESGO
abrir ↗Exploit-DB
Nmap 7.99 - Extension Header Integer Underflow
Nmap - Integer Underflow in IPv6 Extension Header Parsing
33RIESGO
abrir ↗Exploit-DB
Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
61RIESGO
abrir ↗Exploit-DB
mcp-server-kubernetes 3.8.x - Argument Injection
MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
48RIESGO
abrir ↗Exploit-DB
Blocksy Companion 2.1.46 - RCE
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
48RIESGO
abrir ↗Exploit-DB
PraisonAI praisonaiagents 1.6.77 - Remote Code Execution
PraisonAI before 1.6.78 Remote Code Execution via CodeAgent
48RIESGO
abrir ↗Exploit-DB
LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
48RIESGO
abrir ↗Exploit-DB
OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir ↗Exploit-DB
Joomla 2.9.99.4 - Unauthenticated Remote Code Execution
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
100RIESGO
abrir ↗Exploit-DB
Microsoft Edge 150.0.4078.48 - RCE
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
48RIESGO
abrir ↗Exploit-DB
Krayin CRM v2.2.x - Authenticated Remote Code Execution
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a
48RIESGO
abrir ↗Exploit-DB
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
WordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
56RIESGO
abrir ↗Exploit-DB
Langflow 1.9.0 - RCE
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir ↗Exploit-DB
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0
75RIESGO
abrir ↗Exploit-DB
Tenable Nessus 10.12.1 - SQL Injection
SQL Injection in Nessus via Malicious Scan Result File Import
28RIESGO
abrir ↗Exploit-DB
WordPress Bricks Builder Theme - RCE
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir ↗Exploit-DB
MCPJam Inspector - Remote Code Execution
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir ↗Exploit-DB
Flowise 3.1.3 - arbitrary code execution
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RIESGO
abrir ↗Exploit-DB
Hydra - Stack Buffer Overflow
Hydra - Stack Buffer Overflow in NTLM Authentication Handler
41RIESGO
abrir ↗Exploit-DB
Discuz! X5.0 - Authentication Bypass
Discuz! X5.0 Authentication Bypass via dbbak.php Encryption Oracle
63RIESGO
abrir ↗Exploit-DB
WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)
WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vulnerability
56RIESGO
abrir ↗Exploit-DB
KeepInMind 0.8.4.2 - Stored XSS
KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS
33RIESGO
abrir ↗Exploit-DB
Joomla Extension 4.1.4 - PHP Object injection
Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4
63RIESGO
abrir ↗Exploit-DB
MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e
41RIESGO
abrir ↗Exploit-DB
Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass
Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user files
48RIESGO
abrir ↗página 1 / 816siguiente →
Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.