Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.573GitHub PoC 14.316VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.549 exploits
Referência✓ VexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RIESGO
abrir ↗Referência
CVE-2014-3961
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo
23RIESGO
abrir ↗Referência
CVE-2014-3974
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject
23RIESGO
abrir ↗Referência
CVE-2014-4033
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows
23RIESGO
abrir ↗Referência
CVE-2014-4113
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Referência
CVE-2014-4138
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir ↗Referência
CVE-2014-4311
Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mai
23RIESGO
abrir ↗Referência
CVE-2014-4312
Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote
23RIESGO
abrir ↗Referência
CVE-2014-4492
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RIESGO
abrir ↗Referência
CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir ↗Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RIESGO
abrir ↗Referência
CVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje
23RIESGO
abrir ↗Referência
CVE-2009-4386
SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe
23RIESGO
abrir ↗Referência
CVE-2009-4423
SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2009-4432
SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2026-19821
Tenda AC12 httpd web management interface SetSysAutoRebbotCfg formSetRebootTimer buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-19815
TOTOLINK A800R firewall.so cstecgi.cgi setParentalRules stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2015-4027
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RIESGO
abrir ↗Referência
CVE-2015-4039
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent
23RIESGO
abrir ↗Referência
CVE-2026-19814
TOTOLINK A800R firewall.so cstecgi.cgi setMacQos stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-19813
TOTOLINK A800R firewall.so cstecgi.cgi setMacFilterRules stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-19792
Tenda G0 httpd web management interface module setPortMapping buffer overflow
41RIESGO
abrir ↗Referência
CVE-2026-19787
SourceCodester Air Cargo Management System Master.php save_cargo_type sql injection
33RIESGO
abrir ↗Referência
CVE-2026-19784
francoisjacquet RosarioSIS Referrals.php DBUpdate authorization
33RIESGO
abrir ↗Referência
CVE-2026-19770
feedmob fm-mcp-servers Download Endpoint index.ts downloadReport server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-19767
itsourcecode Hospital Management System viewdoctortimings.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-19765
eyaushev swagger-testcase-mcp fetch_swagger swagger-parser.ts loadSource server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-19764
Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-19762
DTStack Taier Chunk-Check Endpoint FileChunkController.java Paths.ge path traversal
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.