Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência
CVE-2023-23333
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir ↗Referência
CVE-2017-10273
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vizayn Haber - 'haberdetay.asp?id' SQL Injection
SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2017-11914
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RIESGO
abrir ↗Referência✓ VexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RIESGO
abrir ↗Referência✓ VexDay Proof
Uberghey 0.3.1 - 'FrontPage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oreon 1.2.3 RC4 - '/lang/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2017-12930
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RIESGO
abrir ↗Referência
CVE-2026-15150
myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED
33RIESGO
abrir ↗Referência
CVE-2017-13772
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated
35RIESGO
abrir ↗Referência
CVE-2026-77025
itsourcecode Hospital Management System viewappointmentpending.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-16616
Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Traversal
41RIESGO
abrir ↗Referência
CVE-2026-15253
Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title
33RIESGO
abrir ↗Referência
CVE-2026-14826
Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR
28RIESGO
abrir ↗Referência
CVE-2026-14825
Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDOR
28RIESGO
abrir ↗Referência
CVE-2026-14334
Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SVG File Upload
41RIESGO
abrir ↗Referência
CVE-2017-14075
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir ↗Referência
CVE-2017-14087
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyNews 4.2.2 - 'themefunc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
ACDSee 9.0 - '.xpm' Local Buffer Overflow
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RIESGO
abrir ↗Referência✓ VexDay Proof
XnView 1.90.3 - '.xpm' Local Buffer Overflow
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a craft
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! 1.5.0 Beta - 'pcltar.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RIESGO
abrir ↗Referência
CVE-2017-15960
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
23RIESGO
abrir ↗Referência
CVE-2017-15961
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
23RIESGO
abrir ↗Referência
CVE-2017-15961
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
23RIESGO
abrir ↗Referência
CVE-2026-75078
SourceCodester Class and Exam Timetabling System BSHRM1.php cross site scripting
33RIESGO
abrir ↗Referência
Microsoft Windows 11 - Kernel Privilege Escalation
Windows Kernel Elevation of Privilege Vulnerability
83RIESGO
abrir ↗Referência
CVE-2017-15963
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser pa
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.