Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
ReferênciaVexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
CVE-2008-4901webappsphp
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Article Publisher PRO - 'userid' SQL Injection
CVE-2008-4902webappsphp
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
CVE-2008-4912webappsphp
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
CVE-2008-4919remotewindows
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
CVE-2008-4922remotewindows
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir
ReferênciaVexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
CVE-2008-4923remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
CVE-2008-4924remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Datamatrix - ActiveX 'Datamatrix.dll' Insecure Method
CVE-2008-4925remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, Da
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 PDF417 - ActiveX 'MW6PDF417.dll' Remote Insecure Method
CVE-2008-4926remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll)
23RIESGO
abrir
ReferênciaVexDay Proof
U-Mail Webmail 4.91 - 'edit.php' Arbitrary File Write
CVE-2008-4932webappsphp
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files v
23RIESGO
abrir
ReferênciaVexDay Proof
PHPX 3.5.16 - 'news_id' SQL Injection
CVE-2008-5000webappsphp
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Bloggie Lite 0.0.2 Beta - Insecure Cookie Handling / SQL Injection
CVE-2008-5004webappsphp
SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2008-5037
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
FTP Now 2.6 Server - Response Remote Crash (PoC)
CVE-2008-5045doswindows
Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to caus
23RIESGO
abrir
Referência
CVE-2026-19195
V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
41RIESGO
abrir
ReferênciaVexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5123webappsphp
SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2026-19193
Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
41RIESGO
abrir
Referência
CVE-2026-19108
MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
33RIESGO
abrir
Referência
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
28RIESGO
abrir
Referência
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
41RIESGO
abrir
Referência
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
41RIESGO
abrir
Referência
CVE-2026-19062
chiuwingyan house selectall.action sql injection
33RIESGO
abrir
Referência
CVE-2026-16067
Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
33RIESGO
abrir
Referência
CVE-2026-15256
Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
33RIESGO
abrir
Referência
CVE-2026-17032
Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
48RIESGO
abrir
Referência
CVE-2026-13342
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
33RIESGO
abrir
Referência
CVE-2026-15149
WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
33RIESGO
abrir
Referência
CVE-2026-15208
RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
33RIESGO
abrir
ReferênciaVexDay Proof
Pro Chat Rooms 3.0.3 - SQL Injection
CVE-2008-5070webappsphp
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2018-6888
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro
23RIESGO
abrir
anteriorpágina 506 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.