Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.233 exploits
Referência
CVE-2026-11585
CodeAstro Student Attendance Management System createClassArms.php sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
Top Auction 1.0 - 'viewcat.php' SQL Injection
CVE-2005-3952webappsphp
SQL injection vulnerability in PHP Labs Top Auction allows remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir
Referência
CVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RIESGO
abrir
Referência
CVE-2026-8777
Edimax BR-6428NS POST Request formStaDrvSetup command injection
33RIESGO
abrir
Referência
CVE-2026-8776
Edimax BR-6428NS POST Request formPPTPSetup buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7315
eiceblue spire-pdf-mcp-server PDF File server.py get_pdf_path path traversal
33RIESGO
abrir
Referência
CVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RIESGO
abrir
Referência
CVE-2017-17578
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RIESGO
abrir
Referência
CVE-2017-17578
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RIESGO
abrir
Referência
CVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RIESGO
abrir
Referência
CVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Pizza - 'manufacturers_id' SQL Injection
CVE-2008-5046webappsphp
SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Rental Script - Authentication Bypass
CVE-2008-5047webappsphp
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
CVE-2008-5049localwindows
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RIESGO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir
Referência
CVE-2026-49136
Banana Slides 0.4.0 Path Traversal via generate_image() in ai_service.py
21RIESGO
abrir
Referência
CVE-2026-43624
F5-TTS 1.1.20 Path Traversal via finetune_gradio.py create_data_project()
21RIESGO
abrir
Referência
CVE-2026-43623
microtar 0.1.0 Stack-Based Buffer Overflow via raw_to_header()
21RIESGO
abrir
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
CVE-2008-5216webappsphp
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RIESGO
abrir
Referência
CVE-2017-17623
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RIESGO
abrir
Referência
CVE-2010-3428
SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
wPortfolio 0.3 - Admin Password Changing
CVE-2008-5221webappsphp
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir
Referência
CVE-2017-17624
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir
ReferênciaVexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
CVE-2008-5223webappsphp
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
anteriorpágina 426 / 742siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.