Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Referência
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir ↗Referência
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Referência
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir ↗Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir ↗Referência
CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir ↗Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir ↗Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir ↗Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
33RIESGO
abrir ↗Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RIESGO
abrir ↗Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11510
CodeAstro Leave Management System add_leave.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11477
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
33RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Unsafe Method
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RIESGO
abrir ↗Referência
CVE-2026-75797
AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter
41RIESGO
abrir ↗Referência
CVE-2026-19094
Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters
33RIESGO
abrir ↗Referência
CVE-2026-58053
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
48RIESGO
abrir ↗Referência
CVE-2026-58052
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
33RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.