Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência
CVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RIESGO
abrir ↗Referência
CVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php
23RIESGO
abrir ↗Referência
CVE-2017-17636
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir ↗Referência
CVE-2004-2502
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RIESGO
abrir ↗Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RIESGO
abrir ↗Referência
CVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diag
23RIESGO
abrir ↗Referência
CVE-2017-17738
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Core - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Core module for Xoops allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Library - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Library module for Xoops allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Tutoriais - 'viewcat.php' SQL Injection
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to inclu
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2017-8594
Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute
35RIESGO
abrir ↗Referência✓ VexDay Proof
Vizayn Urun Tanitim Sistemi 0.2 - 'tr' SQL Injection
SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RIESGO
abrir ↗Referência
CVE-2017-17598
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.
23RIESGO
abrir ↗Referência
CVE-2021-35312
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv
23RIESGO
abrir ↗Referência
CVE-2021-35323
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RIESGO
abrir ↗Referência
CVE-2017-3106
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RIESGO
abrir ↗Referência
CVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RIESGO
abrir ↗Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Ademco co. ltd. ATNBaseLoader100 Module - Remote Buffer Overflow
Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6,
35RIESGO
abrir ↗Referência
CVE-2026-58478
Sustainable Irrigation Platform 5.2.16 SSRF via Node-RED Callback URL
33RIESGO
abrir ↗Referência
CVE-2026-15622
poco-ai poco-claw Workspace API workspace.py get_workspace_file authorization
33RIESGO
abrir ↗Referência
CVE-2026-15595
SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.