Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'base_include.php' Remote File Inclusion
PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
pandaBB - 'displayCategory' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB modu
23RIESGO
abrir ↗Referência
CVE-2026-16565
Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API
33RIESGO
abrir ↗Referência
CVE-2026-16564
Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint
33RIESGO
abrir ↗Referência
CVE-2026-16563
Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint
33RIESGO
abrir ↗Referência
CVE-2026-16539
SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication
41RIESGO
abrir ↗Referência
CVE-2026-13340
SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass
33RIESGO
abrir ↗Referência
CVE-2015-1158
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir ↗Referência
CVE-2014-7863
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir ↗Referência
CVE-2026-16256
Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
48RIESGO
abrir ↗Referência
CVE-2026-15248
Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR
33RIESGO
abrir ↗Referência
CVE-2026-15241
ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response
41RIESGO
abrir ↗Referência
CVE-2026-14309
Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
41RIESGO
abrir ↗Referência
CVE-2014-8295
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência
CVE-2014-8356
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RIESGO
abrir ↗Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RIESGO
abrir ↗Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RIESGO
abrir ↗Referência
CVE-2014-8386
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2014-8555
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attack
23RIESGO
abrir ↗Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Referência
CVE-2014-8722
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<user
28RIESGO
abrir ↗Referência✓ VexDay Proof
DataTrac Activity Console - Denial of Service
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RIESGO
abrir ↗Referência
CVE-2011-5130
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RIESGO
abrir ↗Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir ↗Referência
CVE-2020-11108
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir ↗Referência
CVE-2026-16228
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
33RIESGO
abrir ↗Referência
CVE-2014-8739
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir ↗Referência
CVE-2017-1274
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.