Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.301GitHub PoC 14.141VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
CVE-2019-0735
An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to proper
23RIESGO
abrir ↗Referência
CVE-2016-7188
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RIESGO
abrir ↗Referência
CVE-2016-0093
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir ↗Referência
CVE-2017-17062
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Referência
CVE-2017-17062
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Referência✓ VexDay Proof
pafileDB 2.0.1 - 'mxBB'/'phpBB' Remote File Inclusion
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as us
23RIESGO
abrir ↗Referência
CVE-2023-33863
SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-
48RIESGO
abrir ↗Referência
CVE-2026-14870
Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
41RIESGO
abrir ↗Referência
CVE-2019-15999
Cisco Data Center Network Manager JBoss EAP Unauthorized Access Vulnerability
33RIESGO
abrir ↗Referência
CVE-2016-0728
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗Referência
CVE-2026-14821
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
28RIESGO
abrir ↗Referência
CVE-2026-14545
TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset
48RIESGO
abrir ↗Referência
CVE-2023-36348
POS Codekop v2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the filename p
23RIESGO
abrir ↗Referência✓ VexDay Proof
DynamicPAD 1.02.18 - 'HomeDir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DynamicPAD before 1.03.31 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
openPHPNuke 2.3.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ HYIP ACME - 'topic_detail.php' SQL Injection
SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to
23RIESGO
abrir ↗Referência
CVE-2019-6214
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RIESGO
abrir ↗Referência
CVE-2010-1308
Directory traversal vulnerability in the SVMap (com_svmap) component 1.1.1 for Joomla! allows remote attackers to read a
43RIESGO
abrir ↗Referência✓ VexDay Proof
Synactis All_IN_THE_BOX ActiveX 3.0 - Null Byte File Overwrite
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX
23RIESGO
abrir ↗Referência
CVE-2011-1865
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Referência
CVE-2026-17531
unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
28RIESGO
abrir ↗Referência✓ VexDay Proof
TinyFTPD 1.4 - 'USER' Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a l
23RIESGO
abrir ↗Referência
CVE-2016-3411
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Referência
CVE-2018-12603
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RIESGO
abrir ↗Referência
CVE-2018-12603
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RIESGO
abrir ↗Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.