Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.331exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.484VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Ingress-NGINX 4.11.0 - Remote Code Execution (RCE)
ingress-nginx admission controller RCE escalation
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DocsGPT 0.12.0 - Remote Code Execution
Remote Code Execution in DocsGPT
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Social-Commerce 3.1.6 - Reflected XSS
mooSocial mooStore cross site scripting
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mooSocial 3.1.8 - Reflected XSS
mooSocial mooStore index cross site scripting
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Uvdesk v1.1.3 - File Upload Remote Code Execution (RCE) (Authenticated)
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafte
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin AN_Gradebook 5.0.1 - SQLi
AN_GradeBook <= 5.0.1 - Subscriber+ SQLi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RosarioSIS 10.8.4 - CSV Injection
RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
copyparty v1.8.6 - Reflected Cross Site Scripting (XSS)
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Piggery Management System v1.0 - unauthenticated file upload vulnerability
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by send
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Super Socializer 7.13.52 - Reflected XSS
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SPIP v4.2.0 - Remote Code Execution (Unauthenticated)
SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. T
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PyLoad 0.5.0 - Pre-auth Remote Code Execution (RCE)
Code Injection in pyload/pyload
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sales Tracker Management System v1.0 - Multiple Vulnerabilities
SourceCodester Sales Tracker Management System cross site scripting
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Security Guards Hiring System 1.0 - Reflected XSS
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Faculty Evaluation System 1.0 - Unauthenticated File Upload
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_u
61RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Camaleon CMS v2.7.0 - Server-Side Template Injection (SSTI)
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit CMS v3.14.1 - Stored Cross-Site Scripting (XSS) (Authenticated)
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's securit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GetSimple CMS v3.3.16 - Remote Code Execution (RCE)
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete
46RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Pizza Ordering System v1.0 - Unauthenticated File Upload
SourceCodester Online Pizza Ordering System unrestricted upload
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bang Resto v1.0 - 'Multiple' SQL Injection
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bang Resto v1.0 - Stored Cross-Site Scripting (XSS)
Bang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! v4.2.8 - Unauthenticated information disclosure
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
SourceCodester Employee Task Management System task-details.php sql injection
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
SourceCodester Auto Dealer Management System Users.php access control
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - Broken Authentication
SourceCodester Employee Task Management System changePasswordForEmployee.php improper authentication
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - Broken Access Control
SourceCodester Music Gallery Site POST Request Users.php access control
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RIESGO
abrir ↗página 1 / 636siguiente →
Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.