Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
ReferênciaVexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
CVE-2007-3162doswindows
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RIESGO
abrir
Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RIESGO
abrir
Referência
CVE-2026-11516
UTT HiPER 2610G formNatStaticMap strcpy buffer overflow
33RIESGO
abrir
Referência
CVE-2026-11510
CodeAstro Leave Management System add_leave.php sql injection
33RIESGO
abrir
Referência
CVE-2021-47984
WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS
33RIESGO
abrir
Referência
CVE-2026-11477
hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect
33RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component - Unsafe Method
CVE-2007-3168remotewindows
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RIESGO
abrir
Referência
CVE-2026-15510
Leantime API saveSetting improper authorization
33RIESGO
abrir
Referência
CVE-2026-14746
code-projects Real State Services addprojectrent.php sql injection
33RIESGO
abrir
Referência
CVE-2026-14745
code-projects Real State Services single-list_rent.php sql injection
33RIESGO
abrir
Referência
CVE-2026-14738
exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
33RIESGO
abrir
Referência
CVE-2026-14737
Hanwang e-Face General Management Platform querySysAuthStr.do sql injection
33RIESGO
abrir
Referência
CVE-2026-15387
Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab
33RIESGO
abrir
Referência
CVE-2026-18252
Inclusion of Functionality from Untrusted Control Sphere in GitLab
41RIESGO
abrir
Referência
CVE-2026-9348
Edimax EW-7438RPn webs mp stack-based overflow
41RIESGO
abrir
Referência
CVE-2018-0974
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RIESGO
abrir
Referência
CVE-2018-1002002
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RIESGO
abrir
Referência
CVE-2017-17643
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RIESGO
abrir
Referência
CVE-2017-17643
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RIESGO
abrir
Referência
CVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RIESGO
abrir
Referência
CVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RIESGO
abrir
Referência
CVE-2026-79622
dekdee adobe-xd-mcp file-access-from-request Endpoint xd-parser.ts path traversal
33RIESGO
abrir
Referência
CVE-2026-57863
Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint
41RIESGO
abrir
Referência
CVE-2026-78435
Faveo Helpdesk Logo SettingsController.php unlink path traversal
33RIESGO
abrir
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2016-4372
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RIESGO
abrir
ReferênciaVexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
CVE-2021-35448localwindows
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RIESGO
abrir
anteriorpágina 729 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.