Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2016-0173
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir ↗Referência
CVE-2016-0173
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir ↗Referência
CVE-2016-0491
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir ↗Referência
CVE-2026-16630
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
33RIESGO
abrir ↗Referência
CVE-2016-0709
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3
60RIESGO
abrir ↗Referência
CVE-2026-69110
OpenCode Studio < 2.4.4 Unauthenticated File Read via /api/tmp and /api/music
48RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB News Defilante Horizontale 4.1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and ear
23RIESGO
abrir ↗Referência
CVE-2016-0710
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB SearchIndexer Mod - 'archive_topic.php' Remote File Inclusion
PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Specimen Image Database - 'client.php' Remote File Inclusion
PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when regis
23RIESGO
abrir ↗Referência
CVE-2016-0891
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acunetix WVS 4.0 20060717 - HTTP Sniffer Component Remote Denial of Service
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of ser
23RIESGO
abrir ↗Referência
CVE-2026-59255
BloodHound Missing Authorization on Custom Node Management API
41RIESGO
abrir ↗Referência
CVE-2026-58660
Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop
41RIESGO
abrir ↗Referência
CVE-2026-16014
code-projects Hospital Bed Management System Login Form sql injection
33RIESGO
abrir ↗Referência
CVE-2016-1721
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authent
23RIESGO
abrir ↗Referência
CVE-2016-2107
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência
CVE-2016-2388
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RIESGO
abrir ↗Referência
CVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir ↗Referência
CVE-2026-16130
nearai ironclaw write_file path_utils.rs validate_path link following
33RIESGO
abrir ↗Referência
CVE-2026-16129
princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist
33RIESGO
abrir ↗Referência
CVE-2026-16128
zevorn rt-claw http_request swarm.c receiver_thread server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-16126
zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.