Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.266 exploits
Referência
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗Referência
CVE-2019-10149
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗Referência
CentOS Web Panel 0.9.8.789 - NameServer Field Persistent Cross-Site Scripting
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel
23RIESGO
abrir ↗Referência
CVE-2019-10664
Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
23RIESGO
abrir ↗Referência
CVE-2011-1715
Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other
23RIESGO
abrir ↗Referência
TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on
28RIESGO
abrir ↗Referência
CVE-2019-10893
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RIESGO
abrir ↗Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Referência
CentOS Web Panel 0.9.8.793 (Free) / 0.9.8.753 (Pro) - Cross-Site Scripting
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RIESGO
abrir ↗Referência
CVE-2014-0329
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RIESGO
abrir ↗Referência
CVE-2026-6149
code-projects Vehicle Showroom Management System BookVehicleFunction.php sql injection
33RIESGO
abrir ↗Referência
D-Link DI-524 V2.06RU - Multiple Cross-Site Scripting
On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration:
23RIESGO
abrir ↗Referência
CVE-2026-6597
langflow-ai langflow Flow Using API core.py has_api_terms credentials storage
33RIESGO
abrir ↗Referência
CVE-2026-6596
langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-6595
ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection
33RIESGO
abrir ↗Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir ↗Referência
CVE-2026-6184
code-projects Simple Content Management System welcome.php cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-6183
code-projects Simple Content Management System index.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6158
Totolink N300RH upgrade.so setUpgradeUboot os command injection
33RIESGO
abrir ↗Referência
CVE-2026-6156
Totolink A7100RU CGI cstecgi.cgi setIpQosRules os command injection
48RIESGO
abrir ↗Referência
CVE-2026-6155
Totolink A7100RU CGI cstecgi.cgi setWanCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-6154
Totolink A7100RU CGI cstecgi.cgi setWizardCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2026-6153
code-projects Vehicle Showroom Management System StaffDetailsFunction.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6152
code-projects Vehicle Showroom Management System StaffAddingFunction.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6151
code-projects Vehicle Showroom Management System PaymentStatusFunction.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-6150
code-projects Simple Laundry System checkupdatestatus.php cross site scripting
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.