Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.395exploits catalogados
34.906CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.861GitHub PoC 13.900VulnCheck XDB 8484Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
21.797 exploits
Referência
CVE-2026-18614
GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection
45RIESGO
abrir ↗Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir ↗Referência
CVE-2018-5315
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir ↗Referência
CVE-2026-18613
GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
45RIESGO
abrir ↗Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RIESGO
abrir ↗Referência
CVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.
23RIESGO
abrir ↗Referência
CVE-2026-18612
GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection
45RIESGO
abrir ↗Referência
CVE-2013-4092
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent att
23RIESGO
abrir ↗Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RIESGO
abrir ↗Referência
CVE-2016-1247
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RIESGO
abrir ↗Referência
CVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2021-47964
Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager
41RIESGO
abrir ↗Referência
CVE-2014-9412
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers
23RIESGO
abrir ↗Referência
CVE-2014-7200
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extensi
23RIESGO
abrir ↗Referência✓ VexDay Proof
East Wind Software - 'advdaudio.ocx 1.5.1.1' Local Buffer Overflow
Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
March Networks DVR 3204 - Logfile Information Disclosure
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RIESGO
abrir ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RIESGO
abrir ↗Referência
CVE-2016-1846
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RIESGO
abrir ↗Referência
CVE-2017-11333
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência
CVE-2009-3535
Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência
CVE-2014-8375
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB keyword_replacer 1.0 - 'pathToFiles' File Inclusion
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a
23RIESGO
abrir ↗Referência
CVE-2018-1123
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection
28RIESGO
abrir ↗Referência
CVE-2026-67612
OpenEMR 8.2.0 Stored XSS via import_template.php Template Management
30RIESGO
abrir ↗Referência✓ VexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RIESGO
abrir ↗Referência
CVE-2016-1610
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo
28RIESGO
abrir ↗Referência
CVE-2026-67611
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.