Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8635Nuclei 4274Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.266 exploits
Referência
CVE-2026-5635
PHPGurukul Online Shopping Portal Project Parameter categorywise-products.php sql injection
33RIESGO
abrir ↗Referência
CVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir ↗Referência
CVE-2026-7746
SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection
33RIESGO
abrir ↗Referência
CVE-2017-7358
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar
23RIESGO
abrir ↗Referência
CVE-2017-7411
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RIESGO
abrir ↗Referência
CVE-2017-7411
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RIESGO
abrir ↗Referência
CVE-2010-5008
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2017-7457
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
23RIESGO
abrir ↗Referência
CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Referência
CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Referência
CVE-2026-5557
badlogic pi-mono pi-mom Slack Bot slack.ts authentication bypass
33RIESGO
abrir ↗Referência
CVE-2026-5556
badlogic pi-mono loader.ts discoverAndLoadExtensions code injection
33RIESGO
abrir ↗Referência
CVE-2026-5555
code-projects Concert Ticket Reservation System Parameter login.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5554
code-projects Concert Ticket Reservation System Parameter process_search.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5553
itsourcecode Online Cellphone System Parameter available.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5552
PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5551
itsourcecode Free Hotel Reservation System Parameter login.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5549
Tenda AC10 RSA 2048-bit Private Key privkeySrv.pem hard-coded key
33RIESGO
abrir ↗Referência
CVE-2026-5546
Campcodes Complete Online Learning Management System Crud_model.php add_lesson unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-5543
PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5542
code-projects Simple Laundry System Parameter modstaffinfo.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5541
code-projects Simple Laundry System Parameter modmemberinfo.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5540
code-projects Simple Laundry System Parameter modifymember.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5539
code-projects Simple Laundry System Parameter modifymember.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-5537
halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection
33RIESGO
abrir ↗Referência
CVE-2026-5532
ScrapeGraphAI scrapegraph-ai GenerateCodeNode generate_code_node.py create_sandbox_and_execute os command injection
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.