Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8635Nuclei 4274Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.233 exploits
Referência✓ VexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPhotoalbum 0.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in PHPhotoalbum 0.5 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2017-16928
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RIESGO
abrir ↗Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RIESGO
abrir ↗Referência
CVE-2014-8727
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RIESGO
abrir ↗Referência✓ VexDay Proof
plx Ad Trader 3.2 - 'adid' SQL Injection
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2009-4617
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attacker
23RIESGO
abrir ↗Referência
CVE-2017-15959
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-200
23RIESGO
abrir ↗Referência
CVE-2010-3131
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RIESGO
abrir ↗Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RIESGO
abrir ↗Referência
CVE-2015-3202
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RIESGO
abrir ↗Referência✓ VexDay Proof
Live Music Plus 1.1.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - 'story.php' SQL Injection
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyCard 1.0.2 - 'id' SQL Injection
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
AIOCP 1.4 - 'poll_id' SQL Injection
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mediatheka 4.2 - Blind SQL Injection
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RIESGO
abrir ↗Referência
CVE-2011-4811
SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2023-29689
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RIESGO
abrir ↗Referência
CVE-2009-5003
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência
CVE-2009-5003
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência
CVE-2006-3822
SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to ex
23RIESGO
abrir ↗Referência
CVE-2026-14827
Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
33RIESGO
abrir ↗Referência
CVE-2017-15960
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
23RIESGO
abrir ↗Referência✓ VexDay Proof
WBB2-Addon: Acrotxt 1.0 - 'show' SQL Injection
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2017-15960
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
23RIESGO
abrir ↗Referência
CVE-2017-15961
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.