Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.407GitHub PoC 14.247VulnCheck XDB 8663Nuclei 4287Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência✓ VexDay Proof
Shader TV (Beta) - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrar
23RIESGO
abrir ↗Referência
CVE-2023-3460
Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation
60RIESGO
abrir ↗Referência✓ VexDay Proof
FluentCMS - 'view.php' SQL Injection
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
miniBloggie 1.0 - 'del.php' Arbitrary Delete Post
del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_i
23RIESGO
abrir ↗Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Dating 1.0 - 'view_profile.php' SQL Injection
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction Pro - 'subcat.php' SQL Injection
SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPwebnews 0.2 MySQL Edition - 'det' SQL Injection
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPwebnews 0.2 MySQL Edition - 'id_kat' SQL Injection
SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component SimpleBoard 1.0.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component DBQuery 1.4.1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.6.1 - 'module_pages_site.php' Local File Inclusion
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to i
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPLD 3.3 - Blind SQL Injection
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_qu
23RIESGO
abrir ↗Referência
CVE-2026-7306
Xuxueli xxl-job OpenAPI Endpoint OpenApiController.java hard-coded key
33RIESGO
abrir ↗Referência
CVE-2026-7305
Xuxueli xxl-job trigger Endpoint XxlJobServiceImpl.java triggerJob server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-7303
Xuxueli xxl-job Execution Log JobLogController.java logDetailCat resource injection
33RIESGO
abrir ↗Referência
CVE-2026-7297
SourceCodester Pizzafy Ecommerce System ajax.php save_user cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7296
SourceCodester Pizzafy Ecommerce System ajax.php save_order cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7295
SourceCodester Pizzafy Ecommerce System ajax.php save_menu cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-7294
SourceCodester Pizzafy Ecommerce System index.php save_settings cross site scripting
33RIESGO
abrir ↗Referência
CVE-2012-2227
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - 'SaveAs' Remote Buffer Overflow
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.14
28RIESGO
abrir ↗Referência
CVE-2012-2234
Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticat
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.