Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
ReferênciaVexDay Proof
Prozilla Webring Website Script - 'category.php?cat' SQL Injection
CVE-2007-4362webappsphp
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
CVE-2007-4368webappscgi
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack
23RIESGO
abrir
Referência
CVE-2017-8489
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2017-8491
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2017-8492
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2017-8536
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir
Referência
CVE-2018-14485
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
28RIESGO
abrir
Referência
CVE-2018-14728
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft SQL Server - Distributed Management Objects Buffer Overflow
CVE-2007-4814remotewindows
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir
Referência
CVE-2017-8841
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b30
23RIESGO
abrir
ReferênciaVexDay Proof
Vantage Linguistics AnswerWorks 4 - API ActiveX Control Buffer Overflow
CVE-2007-6387remotewindows
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Van
35RIESGO
abrir
Referência
CVE-2002-1230
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
Referência
CVE-2017-8870
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir
ReferênciaVexDay Proof
WebED 0.8999a - Multiple Remote File Inclusions
CVE-2007-4815webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers
35RIESGO
abrir
Referência
CVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
ReferênciaVexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
CVE-2007-4816doswindows
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir
ReferênciaVexDay Proof
PhpBlock a8.4 - 'PATH_TO_CODE' Remote File Inclusion
CVE-2008-1776webappsphp
PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote att
28RIESGO
abrir
Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RIESGO
abrir
Referência
CVE-2018-10078
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Forum Service - 'forum' SQL Injection
CVE-2008-1789webappsphp
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2018-10079
Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users
23RIESGO
abrir
Referência
CVE-2018-10256
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir
Referência
CVE-2018-10256
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir
Referência
CVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RIESGO
abrir
Referência
CVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RIESGO
abrir
Referência
CVE-2018-10311
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr
23RIESGO
abrir
Referência
CVE-2018-10314
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
CVE-2008-2036webappsphp
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Referência
CVE-2026-14318
GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
33RIESGO
abrir
Referência
CVE-2026-15235
Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
33RIESGO
abrir
anteriorpágina 732 / 758siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.