Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-6110
FoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injection
33RIESGO
abrir
Referência
CVE-2026-6108
1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection
33RIESGO
abrir
Referência
CVE-2026-6106
1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting
33RIESGO
abrir
Referência
CVE-2026-6105
perfree go-fastdfs-web doInstall InstallController.java improper authorization
33RIESGO
abrir
Referência
CVE-2025-9484
Missing Authorization in GitLab
33RIESGO
abrir
Referência
CVE-2026-1092
Improper Validation of Specified Quantity in Input in GitLab
41RIESGO
abrir
Referência
CVE-2026-1101
Improper Validation of Specified Quantity in Input in GitLab
33RIESGO
abrir
Referência
CVE-2026-1516
Improper Control of Generation of Code ('Code Injection') in GitLab
33RIESGO
abrir
Referência
CVE-2026-1752
Incorrect Authorization in GitLab
33RIESGO
abrir
Referência
CVE-2026-2104
Authorization Bypass Through User-Controlled Key in GitLab
33RIESGO
abrir
Referência
CVE-2026-2619
Incorrect Authorization in GitLab
33RIESGO
abrir
Referência
CVE-2017-7293
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RIESGO
abrir
Referência
CVE-2010-4280
Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary
23RIESGO
abrir
Referência
CVE-2017-7690
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary w
23RIESGO
abrir
Referência
CVE-2026-14440
Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records
41RIESGO
abrir
Referência
CVE-2026-58451
Horde IMP < 7.0.1 Path Traversal via Compose.php img src
41RIESGO
abrir
Referência
CVE-2017-7938
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RIESGO
abrir
Referência
CVE-2017-7953
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
23RIESGO
abrir
Referência
CVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Post Card 1.02 - 'catid' SQL Injection
CVE-2008-6622webappsphp
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
CVE-2008-6624webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
CVE-2008-6632webappsphp
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - 'idresa' SQL Injection
CVE-2008-6633webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idre
23RIESGO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
CVE-2008-6634webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RIESGO
abrir
Referência
CVE-2026-13552
itsourcecode Online Hotel Management System controller.php edit sql injection
33RIESGO
abrir
Referência
CVE-2026-13551
itsourcecode Baptism Information Management System editBaptism.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13550
itsourcecode Baptism Information Management System delbaptism.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13548
itsourcecode Hospital Management System doctortimings.php sql injection
33RIESGO
abrir
Referência
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote atta
23RIESGO
abrir
Referência
CVE-2010-4365
SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote atta
23RIESGO
abrir
anteriorpágina 454 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.