Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Referência
CVE-2026-18853
ZomboDroid Meme Generator App com.zombodroid.MemeGenerator t5.l.c path traversal
33RIESGO
abrir ↗Referência
CVE-2026-18852
epsilla-cloud vectordb Filter expr.cpp ShuntingYard unusual condition
33RIESGO
abrir ↗Referência
CVE-2026-70619
Odysseus Missing Admin Authorization via Embedding Endpoint Routes
41RIESGO
abrir ↗Referência
CVE-2015-8427
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Referência
CVE-2026-14322
Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method
33RIESGO
abrir ↗Referência
CVE-2026-12965
Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking
48RIESGO
abrir ↗Referência
CVE-2015-8428
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Referência
CVE-2025-15673
Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
33RIESGO
abrir ↗Referência
CVE-2015-8431
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyTeam 2.0 - 'smileys_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is e
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RIESGO
abrir ↗Referência✓ VexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Transmit.app 3.5.5 - 'ftps://' URL Handler Heap Buffer Overflow (PoC)
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗Referência
CVE-2016-0094
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir ↗Referência
CVE-2026-14226
Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing
33RIESGO
abrir ↗Referência
CVE-2026-14223
Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR
33RIESGO
abrir ↗Referência
CVE-2016-0099
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyConferences 8.0.2 - 'menu.inc.php' File Inclusion
PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.
23RIESGO
abrir ↗Referência
CVE-2016-0953
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir ↗Referência
CVE-2016-0964
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir ↗Referência
CVE-2016-10009
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.