Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.910 exploits
Referência
CVE-2018-18800
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=
23RIESGO
abrir
Referência
CVE-2018-18801
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=
23RIESGO
abrir
Referência
CVE-2018-18801
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=
23RIESGO
abrir
Referência
CVE-2018-18803
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
23RIESGO
abrir
Referência
CVE-2018-18803
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb
23RIESGO
abrir
Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RIESGO
abrir
Referência
CVE-2018-18805
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
23RIESGO
abrir
Referência
CVE-2026-12976
LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant
33RIESGO
abrir
Referência
CVE-2026-18044
Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch
28RIESGO
abrir
Referência
CVE-2025-15687
Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service
33RIESGO
abrir
Referência
CVE-2018-19041
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RIESGO
abrir
Referência
CVE-2026-8224
Open5GS PCF context.c pcf_sess_set_ipv6prefix denial of service
33RIESGO
abrir
Referência
CVE-2026-8223
Open5GS sm-policies Endpoint pcf_sess_sbi_discover_and_send denial of service
33RIESGO
abrir
Referência
CVE-2026-8222
Open5GS sm-policies Endpoint nbsf-handler.c pcf_nbsf_management_handle_register denial of service
33RIESGO
abrir
Referência
CVE-2026-8221
Devs Palace ERP Online item-save cross site scripting
33RIESGO
abrir
Referência
CVE-2026-8220
Devs Palace ERP Online customer-save cross site scripting
33RIESGO
abrir
Referência
CVE-2026-8219
Devs Palace ERP Online supplier-save cross site scripting
33RIESGO
abrir
Referência
CVE-2026-8218
Devs Palace ERP Online purchase_return_save cross site scripting
33RIESGO
abrir
Referência
CVE-2026-8217
Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
33RIESGO
abrir
Referência
CVE-2026-8217
Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
33RIESGO
abrir
ReferênciaVexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
CVE-2006-5975webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2026-19343
code-projects Task Management System AdminLogin.php sql injection
33RIESGO
abrir
Referência
CVE-2026-19342
code-projects Task Management System Login index.php improper authentication
33RIESGO
abrir
Referência
CVE-2026-19341
UTT HiPER 1200GW pptpSrvGlobalConfig strcpy stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-19229
SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
33RIESGO
abrir
Referência
CVE-2026-19213
WonderTrader Pending Order TraderAdapter.h _undone_qty behavioral workflow
33RIESGO
abrir
ReferênciaVexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
CVE-2006-6063localwindows
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RIESGO
abrir
ReferênciaVexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
CVE-2006-6038webappsphp
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
CVE-2006-6086webappsphp
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2026-19212
WonderTrader TraderATP Cash Trade Conversion WTSTradeDef.hpp uninitialized variable
33RIESGO
abrir
anteriorpágina 756 / 764siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.