Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page view_music_details.php
SourceCodester Music Gallery Site GET Request view_music_details.php sql injection
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
SourceCodester Auto Dealer Management System Users.php access control
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Task Managing System v1.0 - SQL Injection (Unauthenticated)
SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - Broken Access Control
SourceCodester Music Gallery Site POST Request Users.php access control
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on (task-details.php?task_id=?)
SourceCodester Employee Task Management System task-details.php sql injection
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Answerdev 1.0.3 - Account Takeover
Improper Access Control in answerdev/answer
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive FileManager 9.9.5 - Remote Code Execution (RCE)
An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BTCPay Server v1.7.4 - HTML Injection
Improper Neutralization of Equivalent Special Elements in btcpayserver/btcpayserver
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (cid) Unauthenticated
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Roxy WI v6.1.0.0 - Improper Authentication Control
Authentication Bypass in Roxy-wi
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project v1.0 - Reflected Cross-Site Scripting (XSS)
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to e
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WP-file-manager v6.9 - Unauthenticated Arbitrary File Upload leading to RCE
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Art Gallery Management System Project v1.0 - SQL Injection (editid) authenticated
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parame
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Paid Memberships Pro v2.9.8 (WordPress Plugin) - Unauthenticated SQL Injection
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerabilit
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE)
Unauthenticated Remote Code Execution in Roxy-wi
75RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GitLab v15.3 - Remote Code Execution (RCE) (Authenticated)
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.4.x - Buffer Overflow
Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo User Interface library (YUI2) TreeView v2.8.2 - Multiple Reflected Cross Site Scripting (XSS)
Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BoxBilling<=4.22.1.5 - Remote Code Execution (RCE)
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Grafana <=6.2.4 - HTML Injection
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
CSRF key bypass using HTTP methods in zoneminder
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass
Denial of service through logs in zoneminder
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MODX Revolution v2.8.3-pl - Authenticated Remote Code Execution
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Composr-CMS Version <=10.0.39 - Authenticated Remote Code Execution
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bus Pass Management System 1.0 - Cross-Site Scripting (XSS)
Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.