Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Palo Alto Networks Firewalls - Root Remote Code Execution
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'getrusage' Stack Leak Through struct Padding
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vanguard 1.4 - SQL Injection
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multiplex Movie Theater Booking Script 3.1.5 - 'moid' / 'eid' SQL Injection
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Professional Service Script 1.0 - 'service-list?city' SQL Injection
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advanced Real Estate Script 4.0.7 - SQL Injection
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.