Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Referência
CVE-2017-17636
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir
Referência
CVE-2026-9348
Edimax EW-7438RPn webs mp stack-based overflow
41RIESGO
abrir
Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
CVE-2007-4155remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS Forum Module - SQL Injection
CVE-2007-4171webappsphp
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attack
23RIESGO
abrir
Referência
CVE-2026-8771
linlinjava litemall Front-end WeChat API WxGoodsController.java list sql injection
33RIESGO
abrir
Referência
CVE-2026-8770
continuedev continue JSON-RPC Server lsTool.ts lsTool path traversal
33RIESGO
abrir
Referência
CVE-2026-8769
vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption
33RIESGO
abrir
Referência
CVE-2026-8768
vercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-8767
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
28RIESGO
abrir
Referência
CVE-2026-8766
Kilo-Org kilocode Environment Variable config.ts load information disclosure
33RIESGO
abrir
Referência
CVE-2026-8765
Kilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal
33RIESGO
abrir
Referência
CVE-2021-47963
Anote 1.0 Persistent Cross-Site Scripting Leading to Code Execution
33RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Nice Talk 0.9.3 - 'tagid' SQL Injection
CVE-2007-4503webappsphp
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoRecruit 1.4 - 'id' SQL Injection
CVE-2007-4506webappsphp
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
CVE-2007-4528localwindows
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Domino Web Access Upload Module - 'dwa7w.dll' Remote Buffer Overflow
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RIESGO
abrir
Referência
CVE-2017-2478
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2017-2489
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
Referência
CVE-2017-2524
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Referência
CVE-2017-2800
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting
41RIESGO
abrir
Referência
CVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RIESGO
abrir
Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
Referência
CVE-2017-3623
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported ve
28RIESGO
abrir
Referência
CVE-2017-3881
CVE-2017-3881CRITICALbajo ataque
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
anteriorpágina 466 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.