Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.797 exploits
Referência✓ VexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attack
23RIESGO
abrir ↗Referência
CVE-2017-13798
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir ↗Referência
CVE-2009-3515
Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to inc
23RIESGO
abrir ↗Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2014-4034
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attacke
23RIESGO
abrir ↗Referência
CVE-2015-7986
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni
23RIESGO
abrir ↗Referência
CVE-2015-1674
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pr
23RIESGO
abrir ↗Referência✓ VexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir ↗Referência
CVE-2019-9881
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on
43RIESGO
abrir ↗Referência
CVE-2017-15359
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RIESGO
abrir ↗Referência
CVE-2017-2442
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RIESGO
abrir ↗Referência
CVE-2017-2367
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Referência
CVE-2022-4047
Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload
48RIESGO
abrir ↗Referência
CVE-2017-9259
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote atta
23RIESGO
abrir ↗Referência
CVE-2026-6142
tushar-2223 Hotel Management System roomdelete.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component 5.2 - ActiveX Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
AvailScript Article Script - Arbitrary File Upload
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RIESGO
abrir ↗Referência
Webrun 3.6.0.42 - 'P_0' SQL Injection
WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process.
23RIESGO
abrir ↗Referência
CVE-2017-11831
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2,
23RIESGO
abrir ↗Referência
CVE-2013-6937
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência
CVE-2018-19749
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RIESGO
abrir ↗Referência
CVE-2013-1600
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0
28RIESGO
abrir ↗Referência
CVE-2018-5751
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Referência
CVE-2009-3306
PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência
CVE-2018-15716
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.