Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.332 exploits
Referência
CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir ↗Referência✓ VexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RIESGO
abrir ↗Referência
CVE-2026-11510
CodeAstro Leave Management System add_leave.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11507
CodeAstro Leave Management System delete_leave_type.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11501
SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection
33RIESGO
abrir ↗Referência
CVE-2026-11500
Weaviate Static API Key client.go validateConfig authorization
28RIESGO
abrir ↗Referência
CVE-2026-11497
D-Link DCS-5615 Boa Webserver boa.conf least privilege violation
33RIESGO
abrir ↗Referência
CVE-2015-3141
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Limbo CMS 1.0.4.2 - 'catid' SQL Injection
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute a
23RIESGO
abrir ↗Referência
CVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17606
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17606
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17608
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17608
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RIESGO
abrir ↗Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RIESGO
abrir ↗Referência
CVE-2006-2315
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência
CVE-2026-18959
yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal
33RIESGO
abrir ↗Referência
CVE-2026-18958
imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection
33RIESGO
abrir ↗Referência
CVE-2026-70616
boringproxy 0.10.0 Resource Exhaustion DoS via GET /loading endpoint
41RIESGO
abrir ↗Referência
CVE-2026-70615
boringproxy 0.10.0 SSH authorized_keys Injection via Tunnel Creation
41RIESGO
abrir ↗Referência
CVE-2026-69111
Milvus 2.6.22, 3.0.0 Unauthenticated Denial of Service via /management/stop
41RIESGO
abrir ↗Referência
CVE-2026-18927
imranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload
33RIESGO
abrir ↗Referência
CVE-2026-15360
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.