Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2026-6191
itsourcecode Construction Management System equipments.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6190
itsourcecode Construction Management System employees.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6189
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6188
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RIESGO
abrir
Referência
CVE-2026-6187
SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection
33RIESGO
abrir
Referência
CVE-2018-8880
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
28RIESGO
abrir
Referência
CVE-2018-25234
SmartFTP Client 9.0.2615.0 Denial of Service via Host Field
33RIESGO
abrir
Referência
CVE-2018-25233
WebDrive 18.00.5057 Denial of Service via Secure WebDAV
33RIESGO
abrir
Referência
CVE-2018-25232
Softros LAN Messenger 9.2 Denial of Service via Log Files Location
33RIESGO
abrir
Referência
CVE-2018-25231
HeidiSQL 9.5.0.5196 Denial of Service via Preferences
33RIESGO
abrir
Referência
CVE-2018-25230
Free IP Switcher 3.1 Denial of Service via Computer Name
33RIESGO
abrir
Referência
CVE-2018-25229
BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP
33RIESGO
abrir
Referência
CVE-2018-25228
NetSetMan 4.7.1 Workgroup Buffer Overflow Denial of Service
33RIESGO
abrir
Referência
CVE-2018-25227
Valentina Studio 9.0.4 Denial of Service via Host Parameter
33RIESGO
abrir
Referência
CVE-2018-25226
FTPShell Server 6.83 Denial of Service via Account Name
33RIESGO
abrir
Referência
CVE-2018-9206
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Referência
CVE-2018-9238
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RIESGO
abrir
Referência
CVE-2018-9515
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RIESGO
abrir
Referência
CVE-2026-12219
Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection
33RIESGO
abrir
Referência
CVE-2026-12218
Yealink SIP-T46U Web FastCGI Service beforewifitest StartReportInformation stack-based overflow
41RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module books SQL - 'cid' SQL Injection
CVE-2008-0827webappsphp
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.5 - SQL Injection
CVE-2008-0831webappsphp
Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! all
23RIESGO
abrir
Referência
CVE-2013-5120
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Referência
CVE-2013-5121
SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
BeContent 031 - 'id' SQL Injection
CVE-2008-0921webappsphp
SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2019-0232
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Modules Manuales 0.1 - 'cid' SQL Injection
CVE-2008-0922webappsphp
SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2026-12813
activepieces File URL file.ts handleUrlFile server-side request forgery
33RIESGO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1229webappsjsp
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RIESGO
abrir
Referência
CVE-2026-4935
SureTriggers < 1.1.23 – Unauthenticated SQLi
41RIESGO
abrir
anteriorpágina 449 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.