Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.832 exploits
Referência✓ VexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2018-13108
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit
23RIESGO
abrir ↗Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência
CVE-2026-16009
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-12684
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
33RIESGO
abrir ↗Referência
CVE-2026-12585
Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token
41RIESGO
abrir ↗Referência
CVE-2026-15520
GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2026-15518
AREA 17 Twill CMS Media Library Insert FileLibraryController.php storeFile unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-12525
Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator
41RIESGO
abrir ↗Referência
CVE-2026-15523
CodeAstro Simple Online Leave Management System dashboard.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-15522
tugcantopaloglu godot-mcp run_project index.js validatePath path traversal
33RIESGO
abrir ↗Referência
CVE-2026-15521
makafeli n8n-workflow-builder update_node_from_file server.cjs path traversal
33RIESGO
abrir ↗Referência
CVE-2026-15515
Tencent PC Manager QMUDisk Driver qmudisk64.sys uncontrolled search path
41RIESGO
abrir ↗Referência
CVE-2026-15473
Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization
33RIESGO
abrir ↗Referência
CVE-2018-13405
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RIESGO
abrir ↗Referência
CVE-2026-15472
Eleveo Call Recording Software composeEmailAction.do improper authorization
33RIESGO
abrir ↗Referência
CVE-2026-12378
BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection
41RIESGO
abrir ↗Referência
CVE-2025-15668
GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
33RIESGO
abrir ↗Referência
CVE-2025-15667
GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
33RIESGO
abrir ↗Referência
CVE-2026-14713
SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection
33RIESGO
abrir ↗Referência
CVE-2026-14706
code-projects Online Examination Quiz Creation Feature update.php sql injection
33RIESGO
abrir ↗Referência✓ VexDay Proof
Binn SBuilder - 'nid' Blind SQL Injection
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
TutorialCMS 1.02 - 'Username' SQL Injection
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disa
23RIESGO
abrir ↗Referência
CVE-2018-14058
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir ↗Referência
CVE-2026-6896
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.