Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.295exploits catalogados
36.048CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.464VulnCheck XDB 8813Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.657 exploits
Referência
CVE-2026-40517
radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
41RIESGO
abrir ↗Referência
CVE-2026-34413
Xerte Online Toolkits Missing Authentication via connector.php
56RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir ↗Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RIESGO
abrir ↗Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RIESGO
abrir ↗Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir ↗Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir ↗Referência
CVE-2014-0999
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RIESGO
abrir ↗Referência✓ VexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência
CVE-2026-63098
TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint
33RIESGO
abrir ↗Referência✓ VexDay Proof
ThePortal 2.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2026-63094
SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
41RIESGO
abrir ↗Referência✓ VexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir ↗Referência
CVE-2026-16017
mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization
33RIESGO
abrir ↗Referência✓ VexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência
CVE-2017-8926
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
23RIESGO
abrir ↗Referência
CVE-2014-10014
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attacke
23RIESGO
abrir ↗Referência
CVE-2014-10020
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir ↗Referência
CVE-2026-16015
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.