Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.459 exploits
Exploit-DB
Copyparty 1.18.6 - Reflected Cross-Site Scripting (XSS)
copyparty Reflected XSS via Filter Parameter
48RIESGO
abrir ↗Exploit-DB
Adobe ColdFusion 2023.6 - Remote File Read
ColdFusion | Improper Access Control (CWE-284)
100RIESGO
abrir ↗Exploit-DB
Xlight FTP 1.1 - Denial Of Service (DOS)
Xlightftpd Xlight FTP Server Login denial of service
33RIESGO
abrir ↗Exploit-DB
XWiki 14 - SQL Injection via getdeleteddocuments.vm
XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
85RIESGO
abrir ↗Exploit-DB
Mezzanine CMS 6.1.0 - Stored Cross Site Scripting (XSS)
A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers
33RIESGO
abrir ↗Exploit-DB
Linux PAM Environment - Variable Injection Local Privilege Escalation
Pam-config: lpe from unprivileged to allow_active in pam
41RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Operator Surname
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers
33RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via the Chat Transfer Function
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attacke
33RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web sc
33RIESGO
abrir ↗Exploit-DB
Tenda FH451 1.0.0.9 Router - Stack-based Buffer Overflow
Tenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
41RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attac
33RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows att
33RIESGO
abrir ↗Exploit-DB
LiveHelperChat 4.61 - Stored Cross Site Scripting (XSS) via Department Assignment Alias Nick Field
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.
33RIESGO
abrir ↗Exploit-DB
Microsoft Edge Windows 10 Version 1511 - Cross Site Scripting (XSS)
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site script
28RIESGO
abrir ↗Exploit-DB
Discourse 3.1.1 - Unauthenticated Chat Message Access
Unauthenticated access to new private chat messages in Discourse
41RIESGO
abrir ↗Exploit-DB
Simple File List WordPress Plugin 4.2.2 - File Upload to RCE
Simple File List < 4.2.3 - Remote Code Execution
75RIESGO
abrir ↗Exploit-DB
Pie Register WordPress Plugin 3.7.1.4 - Authentication Bypass to RCE
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
68RIESGO
abrir ↗Exploit-DB
MikroTik RouterOS 7.19.1 - Reflected XSS
Cross-site scripting via dst parameter in RouterOS WiFi hotspot
33RIESGO
abrir ↗Exploit-DB
Microsoft Graphics Component Windows 11 Pro (Build 26100+) - Local Elevation of Privileges
Windows Graphics Component Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Exploit-DB
TOTOLINK N300RB 8.54 - Command Execution
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenti
41RIESGO
abrir ↗Exploit-DB
PivotX 3.0.0 RC3 - Remote Code Execution (RCE)
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir ↗Exploit-DB
Keras 2.15 - Remote Code Execution (RCE)
Arbitrary Code Execution via Crafted Keras Config for Model Loading
41RIESGO
abrir ↗Exploit-DB
White Star Software Protop 4.4.2-2024-11-27 - Local File Inclusion (LFI)
A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically
56RIESGO
abrir ↗Exploit-DB
NodeJS 24.x - Path Traversal
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO
46RIESGO
abrir ↗Exploit-DB
Langflow 1.2.x - Remote Code Execution (RCE)
Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
100RIESGO
abrir ↗Exploit-DB
Microsoft Brokering File System Windows 11 Version 22H2 - Elevation of Privilege
Microsoft Brokering File System Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Exploit-DB
SugarCRM 14.0.0 - SSRF/Code Injection
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can
46RIESGO
abrir ↗Exploit-DB
WP Publications WordPress Plugin 1.2 - Stored XSS
WP Publications <= 1.2 - Admin+ Stored XSS
33RIESGO
abrir ↗Exploit-DB
Microsoft PowerPoint 2019 - Remote Code Execution (RCE)
Microsoft PowerPoint Remote Code Execution Vulnerability
41RIESGO
abrir ↗Exploit-DB
Microsoft Defender for Endpoint (MDE) - Elevation of Privilege
Microsoft Defender for Endpoint Elevation of Privilege Vulnerability
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.