Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.302exploits catalogados
35.469CVEs con explotación pública
24.695probados en laboratorio
22.301 exploits
Referência
CVE-2026-24065
Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS
41RIESGO
abrir
Referência
CVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RIESGO
abrir
Referência
CVE-2026-11477
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
33RIESGO
abrir
Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
1st News - SQL Injection
CVE-2008-4890webappsphp
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir
Referência
CVE-2010-3404
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
CVE-2008-4895webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RIESGO
abrir
Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RIESGO
abrir
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Referência
CVE-2026-10875
projectworlds Online Art Gallery Shop Project adminHome.ph sql injection
33RIESGO
abrir
Referência
CVE-2026-10874
projectworlds Online Art Gallery Shop Project adminHome.php sql injection
33RIESGO
abrir
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Pizza - 'manufacturers_id' SQL Injection
CVE-2008-5046webappsphp
SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Rental Script - Authentication Bypass
CVE-2008-5047webappsphp
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
CVE-2008-5049localwindows
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RIESGO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir
Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir
Referência
CVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RIESGO
abrir
Referência
CVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RIESGO
abrir
Referência
CVE-2010-3467
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial modul
23RIESGO
abrir
ReferênciaVexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
CVE-2008-5600webappsphp
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir
anteriorpágina 455 / 744siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.