Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.401exploits catalogados
35.511CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.332GitHub PoC 14.209VulnCheck XDB 8646Nuclei 4289Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.301 exploits
Referência
CVE-2026-7233
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
33RIESGO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2010-4999
SQL injection vulnerability in index.php in esoftpro Online Photo Pro 2.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
CFMBLOG - 'categorynbr' Blind SQL Injection
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
CF_Auction - Blind SQL Injection
SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
CF_Forum - Blind SQL Injection
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
ProQuiz 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência
CVE-2010-3742
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Job Board - Authentication Bypass
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyTopix 1.3.0 - SQL Injection
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
RSS Simple News - SQL Injection
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
PostNuke 0.763 - 'PNSV lang' Remote Code Execution
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and exec
23RIESGO
abrir ↗Referência
CVE-2026-7226
SourceCodester Pizzafy Ecommerce System ajax.php login2 sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7225
SourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7224
SourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injection
33RIESGO
abrir ↗Referência
CVE-2026-7223
BigSweetPotatoStudio HyperChat AI Proxy Middleware aiProxyMiddleware.mts fetch server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RIESGO
abrir ↗Referência
CVE-2010-5000
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RIESGO
abrir ↗Referência
CVE-2010-3765
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to in
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xpoze 4.10 - 'menu' Blind SQL Injection
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.