Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yoga Class Script 1.0 - 'list?city' SQL Injection
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Foodpanda Clone 1.0 - SQL Injection
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advance B2B Script 2.1.3 - 'show_id' / 'pid' SQL Injection
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advance Online Learning Management Script 3.1 - 'subcatid' / 'popcourseid' SQL Injection
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Expedia Clone 1.0 - 'fl_orig' / 'fl_dest' / 'id' SQL Injection
FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS IMDB Clone 1.0 - 'f' / 's' / 'id' SQL Injection
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Indiamart Clone 1.0 - 'token' / 'id' / 'c' SQL Injection
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Trademe Clone 1.0 - 'search' / 'id' SQL Injection
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Gigs Script 1.0 - 'cat' / 'sc' SQL Injection
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Groupon Clone 1.0 - 'id' SQL Injection
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Care Clone 1.0 - 'jobFrequency' / 'jobType' SQL Injection
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Ebay Clone 1.0 - 'id' / 'sub_category_id' / 'category_id' SQL Injection
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Amazon Clone 1.0 - SQL Injection
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Crowdfunding Script 1.0 - 'latest_news_details.php?id' SQL Injection
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Basic B2B Script 2.0.8 - 'product_details.php?id' SQL Injection
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Beauty Parlour Booking Script 1.0 - 'gender' / 'city' SQL Injection
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Grubhub Clone 1.0 - 'keywords' SQL Injection
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FS Linkedin Clone 1.0 - 'grid' / 'fid' / 'id' SQL Injection
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.