Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8617Nuclei 4257Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.175 exploits
Referência
CVE-2010-2459
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2017-1000353
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir ↗Referência
CVE-2017-1000353
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir ↗Referência
CVE-2026-8275
bettercap zerogod IPP Service zerogod_ipp_primitives.go ippReadChunkedBody integer coercion
33RIESGO
abrir ↗Referência
CVE-2018-10828
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RIESGO
abrir ↗Referência
CVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RIESGO
abrir ↗Referência
CVE-2016-1583
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RIESGO
abrir ↗Referência
CVE-2016-1583
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RIESGO
abrir ↗Referência✓ VexDay Proof
Softbiz Jobs & Recruitment - SQL Injection
SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2025-34089
Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
63RIESGO
abrir ↗Referência
CVE-2025-34089
Remote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
63RIESGO
abrir ↗Referência
CVE-2025-34150
Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command Injection
48RIESGO
abrir ↗Referência✓ VexDay Proof
mail2forum phpBB Mod 1.2 - 'm2f_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attacke
23RIESGO
abrir ↗Referência
CVE-2016-8972
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
23RIESGO
abrir ↗Referência
CVE-2010-2464
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla!
23RIESGO
abrir ↗Referência✓ VexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência
CVE-2012-2585
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to injec
23RIESGO
abrir ↗Referência
CVE-2011-5185
Cross-site scripting (XSS) vulnerability in video_comments.php in Online Subtitles Workshop before 2.0 rev 131 allows re
23RIESGO
abrir ↗Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RIESGO
abrir ↗Referência
CVE-2015-7892
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RIESGO
abrir ↗Referência
CVE-2026-8260
D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow
41RIESGO
abrir ↗Referência
CVE-2014-8347
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir ↗Referência
CVE-2014-8347
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.