Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3433webappsphp
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
CVE-2007-3435remotewindows
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RIESGO
abrir
Referência
CVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Sony Network Camera SNC-P5 1.0 - ActiveX viewer Heap Overflow (PoC)
CVE-2007-3488doswindows
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5
28RIESGO
abrir
Referência
CVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Excel 2000/2003 - Sheet Name (PoC)
CVE-2007-3490doswindows
Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified
35RIESGO
abrir
ReferênciaVexDay Proof
phpEventCalendar 0.2.3 - 'eventdisplay.php' SQL Injection
CVE-2007-3519webappsphp
SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ArcadeBuilder Game Portal Manager 1.7 - SQL Injection
CVE-2007-3521webappsphp
SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTicket 1.2 - 'qti_checkname.php' Local File Inclusion
CVE-2007-3547webappsphp
Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute
23RIESGO
abrir
Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Buddy Zone 1.5 - 'view_sub_cat.php?cat_id' SQL Injection
CVE-2007-3549webappsphp
SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
WebChat 0.78 - 'login.php?rid' SQL Injection
CVE-2007-3534webappsphp
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
b1gbb 2.24.0 - SQL Injection / Cross-Site Scripting
CVE-2007-3589webappsphp
Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3607doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3608doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3608doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Referência
CVE-2017-17636
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir
Referência
CVE-2026-10693
SourceCodester Online Boat Reservation System Administrative Endpoint improper authorization
33RIESGO
abrir
Referência
CVE-2026-10661
ahujasid blender-mcp server.py open injection
33RIESGO
abrir
Referência
CVE-2026-10190
Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service
41RIESGO
abrir
Referência
CVE-2026-10187
Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow
48RIESGO
abrir
Referência
CVE-2026-10186
code-projects Online Hospital Management System patient.php sql injection
33RIESGO
abrir
Referência
CVE-2018-25389
HaPe PKH 1.1 SQL Injection via nama_kelompok Parameter
41RIESGO
abrir
Referência
CVE-2026-9477
Totolink A8000RU Web Management cstecgi.cgi setAccessDeviceCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9476
Totolink A8000RU Web Management cstecgi.cgi setPasswordCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9465
Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
33RIESGO
abrir
anteriorpágina 505 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.