Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
48RIESGO
abrir ↗Referência
CVE-2015-5285
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc
23RIESGO
abrir ↗Referência
CVE-2009-3065
PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2018-1203
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0
23RIESGO
abrir ↗Referência
CVE-2006-5209
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 a
23RIESGO
abrir ↗Referência
CVE-2010-2005
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência
CVE-2016-7385
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RIESGO
abrir ↗Referência
CVE-2022-41912
crewjam/saml go library is vulnerable to signature bypass via multiple Assertion elements
48RIESGO
abrir ↗Referência
CVE-2018-11512
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge
23RIESGO
abrir ↗Referência✓ VexDay Proof
Online Rental Property Script 4.5 - 'pid' SQL Injection
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir ↗Referência
CVE-2015-5353
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗Referência
CVE-2016-7612
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir ↗Referência
CVE-2015-8255
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RIESGO
abrir ↗Referência✓ VexDay Proof
xNews 1.3 - 'xNews.php' SQL Injection
SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
CVE-2008-2190
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
ImperialBB 2.3.5 - Arbitrary File Upload
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
X-ice News System 1.0 - 'devami.asp?id' SQL Injection
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2010-0681
ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Friendfinder 3.3 - 'view.php?id' SQL Injection
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2017-14619
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Referência
CVE-2017-14619
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Referência✓ VexDay Proof
pPIM 1.0 - Arbitrary File Delete / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Skype Extension for Firefox Beta 2.2.0.95 - Clipboard Writing
The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência
CVE-2023-27350
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir ↗Referência✓ VexDay Proof
PixelPost 1.7 - Blind SQL Injection
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Uploader 1.1 - 'Filename' File Disclosure
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.