Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2026-9414
SourceCodester Indian Invoicing System Invoice Template Render Database-Backed add_order.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-9413
SourceCodester Indian Invoicing System category.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-9412
SourceCodester Indian Invoicing System Backend Endpoint access control
33RIESGO
abrir
Referência
CVE-2026-9411
SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection
33RIESGO
abrir
Referência
CVE-2026-9410
Sushmi-pal Invoice-System Profile Workflow profile improper authorization
33RIESGO
abrir
Referência
CVE-2026-9405
Totolink A8000RU Web Management cstecgi.cgi setGameSpeedCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-9402
Edimax BR-6675nD POST Request formWlanMP command injection
33RIESGO
abrir
Referência
CVE-2026-9401
Edimax BR-6675nD POST Request formWanTcpipSetup buffer overflow
41RIESGO
abrir
ReferênciaVexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
CVE-2007-0489webappsphp
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RIESGO
abrir
ReferênciaVexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
CVE-2007-0495webappsphp
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
webSPELL 4.01.02 - 'gallery.php' Blind SQL Injection
CVE-2007-0502webappsphp
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
CVE-2007-0511webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RIESGO
abrir
Referência
CVE-2018-25354
Joomla Component jomres 9.11.2 Cross-Site Request Forgery
33RIESGO
abrir
ReferênciaVexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
CVE-2007-0548doswindows
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir
ReferênciaVexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
CVE-2007-0559webappsphp
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RIESGO
abrir
Referência
CVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls
23RIESGO
abrir
Referência
CVE-2009-2385
SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 fo
23RIESGO
abrir
Referência
CVE-2009-2392
SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2009-2400
SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2009-2402
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Remotesoft .NET Explorer 2.0.1 - Local Stack Overflow (PoC)
CVE-2007-0766doswindows
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of
23RIESGO
abrir
Referência
CVE-2021-1497
CVE-2021-1497CRITICALbajo ataque
Cisco HyperFlex HX Command Injection Vulnerabilities
100RIESGO
abrir
Referência
CVE-2022-29303
CVE-2022-29303CRITICALbajo ataque
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
100RIESGO
abrir
ReferênciaVexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
CVE-2007-0785webappsphp
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RIESGO
abrir
ReferênciaVexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
CVE-2007-0786webappsphp
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
CVE-2007-0790doswindows
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir
ReferênciaVexDay Proof
Advanced Poll 2.0.5-dev - Remote Admin Session Generator
CVE-2007-0845webappsphp
admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain admin
23RIESGO
abrir
anteriorpágina 356 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.