Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.053exploits catalogados
34.675CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2026-10661
ahujasid blender-mcp server.py open injection
33RIESGO
abrir
Referência
CVE-2026-10650
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
33RIESGO
abrir
Referência
CVE-2026-10650
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
33RIESGO
abrir
Referência
CVE-2026-10624
SourceCodester Human Resource Management Employee View detailview.php resource injection
33RIESGO
abrir
Referência
CVE-2026-10619
sayan365 student-management-system improper authentication
33RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Nice Talk 0.9.3 - 'tagid' SQL Injection
CVE-2007-4503webappsphp
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoRecruit 1.4 - 'id' SQL Injection
CVE-2007-4506webappsphp
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
CVE-2007-4509webappsphp
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RIESGO
abrir
Referência
CVE-2026-2601
Missing Authorization in GitLab
33RIESGO
abrir
Referência
CVE-2026-4868
Authorization Bypass Through User-Controlled Key in GitLab
41RIESGO
abrir
Referência
CVE-2026-5296
Missing Authorization in GitLab
33RIESGO
abrir
Referência
CVE-2026-6713
Incorrect Authorization in GitLab
33RIESGO
abrir
Referência
CVE-2026-9606
itsourcecode Courier Management System manage_user.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9604
JeecgBoot AiragModelController access control
33RIESGO
abrir
Referência
CVE-2010-5285
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the a
23RIESGO
abrir
ReferênciaVexDay Proof
SunShop Shopping Cart 4.0 RC 6 - 'Search' Blind SQL Injection
CVE-2007-4597webappsphp
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Micro CMS 3.5 - 'revert-content.php' SQL Injection
CVE-2007-4602webappsphp
SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attac
23RIESGO
abrir
Referência
CVE-2010-5299
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir
ReferênciaVexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
CVE-2007-4604webappsphp
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Postcast Server Pro 3.0.61 / Quiksoft EasyMail - 'emsmtp.dll 6.0.1' Remote Buffer Overflow
CVE-2007-4607remotewindows
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RIESGO
abrir
Referência
CVE-2010-5299
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir
ReferênciaVexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
CVE-2007-4653webappsphp
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4807webappsphp
Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft SQL Server - Distributed Management Objects Buffer Overflow
CVE-2007-4814remotewindows
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir
ReferênciaVexDay Proof
WebED 0.8999a - Multiple Remote File Inclusions
CVE-2007-4815webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers
35RIESGO
abrir
Referência
CVE-2015-1478
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
RW::Download 2.0.3 lite - 'index.php?dlid' SQL Injection
CVE-2007-4845webappsphp
Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio 6.0 - 'VBTOVSI.dll 1.0.0.0' File Overwrite
CVE-2007-4890remotewindows
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1
28RIESGO
abrir
Referência
CVE-2026-3073
Authorization Bypass Through User-Controlled Key in GitLab
33RIESGO
abrir
ReferênciaVexDay Proof
NuclearBB Alpha 2 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-4906webappsphp
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e
35RIESGO
abrir
anteriorpágina 275 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.