Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.832 exploits
Referência
CVE-2017-20280
Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter
41RIESGO
abrir ↗Referência✓ VexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RIESGO
abrir ↗Referência
CVE-2026-24066
Slate Digital Connect macOS XPC certificate validation privilege escalation
41RIESGO
abrir ↗Referência
CVE-2017-20248
WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
41RIESGO
abrir ↗Referência
CVE-2026-11533
imvks786 student_management_system Student Deletion Endpoint see.php improper authorization
33RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RIESGO
abrir ↗Referência
CVE-2026-11532
imvks786 student_management_system Student Record add.php access control
33RIESGO
abrir ↗Referência
CVE-2026-9067
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload
48RIESGO
abrir ↗Referência
CVE-2026-11557
Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-39908
OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source
41RIESGO
abrir ↗Referência
CVE-2026-11506
CodeAstro Leave Management System search_staff_for_deletion.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11504
Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow
41RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Office Products - Array Index Bounds Error (PoC)
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of
28RIESGO
abrir ↗Referência✓ VexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RIESGO
abrir ↗Referência
CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir ↗Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir ↗Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗Referência
CVE-2018-16763
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗Referência
CVE-2026-10529
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
33RIESGO
abrir ↗Referência
CVE-2026-10276
hekmon8 Jenkins-server-mcp get_build_status/get_build_log/trigger_build index.ts jobPath server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-10275
OpenSC pkcs11-tool Key Generation pkcs11-tool.c test_kpgen_certwrite buffer overflow
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.