Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência✓ VexDay Proof
Multiple Membership Script 2.5 - 'id' SQL Injection
SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2026-9474
yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2014-9418
The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users
23RIESGO
abrir ↗Referência
CVE-2014-9439
Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
BosClassifieds - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência
CVE-2026-16229
itsourcecode Courier Management System index.php cross site scripting
33RIESGO
abrir ↗Referência
eBrigade ERP 4.5 - Arbitrary File Download
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RIESGO
abrir ↗Referência
CVE-2019-9670
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir ↗Referência
CVE-2019-9670
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir ↗Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.mp3' Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wma' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RIESGO
abrir ↗Referência
AirDrop 2.0 - Denial of Service (DoS)
The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m
23RIESGO
abrir ↗Referência
NetData 1.13.0 - HTML Injection
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor
23RIESGO
abrir ↗Referência
CVE-2019-9978
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir ↗Referência
CVE-2026-9366
NousResearch hermes-agent prompt_builder.py _scan_context_content injection
33RIESGO
abrir ↗Referência
CVE-2011-5044
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute
23RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2020-0796
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir ↗Referência
CVE-2015-1538
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗Referência
CVE-2020-10220
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir ↗Referência
CVE-2020-10221
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands vi
83RIESGO
abrir ↗Referência
CVE-2011-5116
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência
PHPKB Multi-Language 9 - 'image-upload.php' Authenticated Remote Code Execution
admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Exe
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.