Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
CVE-2026-41468
Beghelli Sicuro24 SicuroWeb AngularJS Sandbox Escape via Template Injection
48RIESGO
abrir ↗Referência
CVE-2012-2095
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configur
23RIESGO
abrir ↗Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir ↗Referência✓ VexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RIESGO
abrir ↗Referência✓ VexDay Proof
NewzCrawler 1.8 - invalid string Remote Denial of Service
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili
23RIESGO
abrir ↗Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗Referência
CVE-2026-6623
BichitroGan ISP Billing Software Profile users-view cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-6622
BichitroGan ISP Billing Software Customer edit cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-6620
SonicCloudOrg sonic-server File Upload Endpoint FileTool.java upload path traversal
33RIESGO
abrir ↗Referência
CVE-2026-6619
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-6618
langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-6616
TransformerOptimus SuperAGI WebScraperTool webpage_extractor.py extract_with_lxml server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2012-2396
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and applicati
23RIESGO
abrir ↗Referência
CVE-2026-7612
itsourcecode Courier Management System edit_user.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7609
TRENDnet TEW-821DAP Firmware Udpate diagnostic tools_diagnostic os command injection
33RIESGO
abrir ↗Referência
CVE-2026-7545
SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7538
Totolink A8000RU CGI cstecgi.cgi vulnerability os command injection
48RIESGO
abrir ↗Referência
CVE-2026-7536
Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of service
33RIESGO
abrir ↗Referência
CVE-2012-2572
Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote a
23RIESGO
abrir ↗Referência
CVE-2018-17128
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RIESGO
abrir ↗Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir ↗Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir ↗Referência
CVE-2018-17173
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir ↗Referência
CVE-2018-17376
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.