Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2017-0128
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Referência
CVE-2017-0143
CVE-2017-0143HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Referência
CVE-2017-0143
CVE-2017-0143HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.1 with PECL PHPDOC - Local Buffer Overflow
CVE-2007-1709localwindows
Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows contex
23RIESGO
abrir
Referência
CVE-2017-17572
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RIESGO
abrir
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RIESGO
abrir
Referência
CVE-2022-45030
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may
41RIESGO
abrir
Referência
CVE-2017-17584
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
23RIESGO
abrir
Referência
CVE-2026-78112
itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection
33RIESGO
abrir
Referência
CVE-2026-77116
Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview
33RIESGO
abrir
Referência
CVE-2026-77115
Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters
41RIESGO
abrir
Referência
CVE-2026-77003
Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_mask
28RIESGO
abrir
Referência
CVE-2026-14853
WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Authorization
33RIESGO
abrir
Referência
CVE-2026-13598
RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator
23RIESGO
abrir
Referência
CVE-2017-14847
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir
Referência
CVE-2017-14955
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi
28RIESGO
abrir
Referência
CVE-2017-15287
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouq
38RIESGO
abrir
Referência
CVE-2017-15357
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges v
23RIESGO
abrir
Referência
CVE-2017-15580
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly v
28RIESGO
abrir
Referência
CVE-2017-15665
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
23RIESGO
abrir
Referência
CVE-2017-15665
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
23RIESGO
abrir
Referência
CVE-2017-15687
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1
23RIESGO
abrir
Referência
CVE-2018-0973
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
ReferênciaVexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
CVE-2007-1057locallinux
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
CVE-2007-1061webappsphp
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RIESGO
abrir
Referência
CVE-2017-15884
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently su
23RIESGO
abrir
ReferênciaVexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
CVE-2007-1074localwindows
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2017-15918
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial
23RIESGO
abrir
Referência
CVE-2017-15921
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RIESGO
abrir
Referência
CVE-2017-15944
CVE-2017-15944CRITICALbajo ataque
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
anteriorpágina 724 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.