Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.523GitHub PoC 14.289VulnCheck XDB 8710Nuclei 4319Metasploit 3476✓ solo verificadosrecientespopularesriesgo
22.523 exploits
Referência✓ VexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RIESGO
abrir ↗Referência
CVE-2013-6366
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod
23RIESGO
abrir ↗Referência
CVE-2016-7851
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne
23RIESGO
abrir ↗Referência
CVE-2010-4944
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attac
23RIESGO
abrir ↗Referência
CVE-2017-9147
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau
23RIESGO
abrir ↗Referência✓ VexDay Proof
Frequency Clock 0.1b - 'securelib' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RIESGO
abrir ↗Referência
CVE-2015-7896
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RIESGO
abrir ↗Referência
CVE-2015-7896
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RIESGO
abrir ↗Referência
CVE-2010-4332
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RIESGO
abrir ↗Referência
CVE-2017-17097
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RIESGO
abrir ↗Referência
CVE-2014-1637
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a
23RIESGO
abrir ↗Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RIESGO
abrir ↗Referência
CVE-2011-3713
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the
23RIESGO
abrir ↗Referência✓ VexDay Proof
DFLabs PTK 1.0 - Local Command Execution
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RIESGO
abrir ↗Referência
CVE-2010-4975
SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remot
23RIESGO
abrir ↗Referência
CVE-2025-0798
MicroWorld eScan Antivirus Quarantine rtscanner os command injection
48RIESGO
abrir ↗Referência
CVE-2008-6366
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2015-7248
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RIESGO
abrir ↗Referência
CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RIESGO
abrir ↗Referência
CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RIESGO
abrir ↗Referência
CVE-2016-1594
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RIESGO
abrir ↗Referência
CVE-2016-1594
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RIESGO
abrir ↗Referência
CVE-2013-0249
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.