Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.523 exploits
Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Referência
CVE-2019-15092
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RIESGO
abrir ↗Referência
CVE-2019-25699
Newsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
41RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RIESGO
abrir ↗Referência
CVE-2017-13713
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RIESGO
abrir ↗Referência
CVE-2017-13713
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RIESGO
abrir ↗Referência
CVE-2026-58057
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
28RIESGO
abrir ↗Referência
CVE-2017-2482
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir ↗Referência
CVE-2016-0073
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir ↗Referência
CVE-2018-12095
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RIESGO
abrir ↗Referência
CVE-2013-5578
Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows rem
23RIESGO
abrir ↗Referência
CVE-2023-29983
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary co
33RIESGO
abrir ↗Referência
CVE-2017-2447
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Referência
CVE-2017-9127
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a deni
23RIESGO
abrir ↗Referência
CVE-2022-2941
WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
33RIESGO
abrir ↗Referência
CVE-2016-7617
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir ↗Referência
CVE-2009-3752
SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the g
23RIESGO
abrir ↗Referência
CVE-2015-10137
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RIESGO
abrir ↗Referência✓ VexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
MoviePlay 4.76 - '.lst' Local Buffer Overflow
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Login 0.7 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Madirish Webmail 2.0 - 'addressbook.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebChamado 1.1 - Arbitrary Add Admin
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir ↗Referência
CVE-2015-7241
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RIESGO
abrir ↗Referência
CVE-2015-3796
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RIESGO
abrir ↗Referência
CVE-2016-0079
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application
23RIESGO
abrir ↗Referência✓ VexDay Proof
minb 0.1.0 - Remote Code Execution
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.