Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Referência
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir
Referência
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Referência
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir
Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir
Referência
CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir
Referência
CVE-2026-18766
chetans9 core-php-admin-panel customers.php sql injection
33RIESGO
abrir
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir
Referência
CVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Referência
CVE-2026-18646
danpros HTMLy Author Name htmly.php path traversal
33RIESGO
abrir
Referência
CVE-2026-18631
jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization
33RIESGO
abrir
Referência
CVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
23RIESGO
abrir
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir
Referência
CVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
CVE-2007-3162doswindows
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RIESGO
abrir
Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RIESGO
abrir
Referência
CVE-2026-11516
UTT HiPER 2610G formNatStaticMap strcpy buffer overflow
33RIESGO
abrir
Referência
CVE-2026-11510
CodeAstro Leave Management System add_leave.php sql injection
33RIESGO
abrir
Referência
CVE-2021-47984
WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS
33RIESGO
abrir
Referência
CVE-2026-11477
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
33RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component - Unsafe Method
CVE-2007-3168remotewindows
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RIESGO
abrir
Referência
CVE-2026-75797
AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter
41RIESGO
abrir
Referência
CVE-2026-19094
Tutor LMS < 4.0.6 - Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters
33RIESGO
abrir
Referência
CVE-2026-58053
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
48RIESGO
abrir
Referência
CVE-2026-58052
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
33RIESGO
abrir
anteriorpágina 727 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.