Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8703Nuclei 4314Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.429 exploits
Referência
CVE-2019-13235
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RIESGO
abrir ↗Referência
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Referência
CVE-2024-14042
Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow
33RIESGO
abrir ↗Referência
CVE-2022-50997
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp
41RIESGO
abrir ↗Referência
CVE-2016-20097
Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad
41RIESGO
abrir ↗Referência
CVE-2026-9428
Tenda F1202 PPTPUserSetting fromPPTPUserSetting stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2018-25350
userSpice 4.3.24 Username Enumeration via existingUsernameCheck.php
48RIESGO
abrir ↗Referência
CVE-2026-9306
QuantumNous new-api Midjourney Image Relay Endpoint relay-router.go GetByOnlyMJId authorization
33RIESGO
abrir ↗Referência
CVE-2026-9305
QuantumNous new-api self Endpoint topup.go SearchAllTopUps sql injection
33RIESGO
abrir ↗Referência
CVE-2026-9304
calcom cal.diy Logo API route.ts validateUrlForSSRF server-side request forgery
28RIESGO
abrir ↗Referência
CVE-2026-17044
WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid
41RIESGO
abrir ↗Referência
CVE-2026-14767
CodeAstro Ecommerce Website POST Parameter confirm.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14766
CodeAstro Apartment Visitor Management System POST Parameter search-result.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14764
code-projects Hotel and Tourism Reservation Event Management add_event.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14763
code-projects Hotel and Tourism Reservation Tour Reservations tour_reserves.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14762
code-projects Hotel and Tourism Reservation Room Management rooms.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-17014
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips
33RIESGO
abrir ↗Referência
CVE-2026-16992
Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publication
33RIESGO
abrir ↗Referência
CVE-2026-16988
GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint
41RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RIESGO
abrir ↗Referência
CVE-2019-14750
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir ↗Referência
CVE-2019-15081
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe
23RIESGO
abrir ↗Referência
MaxxAudio Drivers WavesSysSvc64.exe 1.6.2.0 - Local Privilege Escalation
Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result,
23RIESGO
abrir ↗Referência
ManageEngine Application Manager 14.2 - Privilege Escalation / Remote Command Execution (Metasploit)
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in
23RIESGO
abrir ↗Referência
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Referência
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.