Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir ↗Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir ↗Referência
CVE-2017-17636
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS Forum Module - SQL Injection
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attack
23RIESGO
abrir ↗Referência
CVE-2026-8771
linlinjava litemall Front-end WeChat API WxGoodsController.java list sql injection
33RIESGO
abrir ↗Referência
CVE-2026-8770
continuedev continue JSON-RPC Server lsTool.ts lsTool path traversal
33RIESGO
abrir ↗Referência
CVE-2026-8769
vercel ai provider-utils response-handler.ts createJsonErrorResponseHandler resource consumption
33RIESGO
abrir ↗Referência
CVE-2026-8768
vercel ai provider-utils download-blob.ts validateDownloadUrl server-side request forgery
33RIESGO
abrir ↗Referência
CVE-2026-8767
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
28RIESGO
abrir ↗Referência
CVE-2026-8766
Kilo-Org kilocode Environment Variable config.ts load information disclosure
33RIESGO
abrir ↗Referência
CVE-2026-8765
Kilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal
33RIESGO
abrir ↗Referência
CVE-2021-47963
Anote 1.0 Persistent Cross-Site Scripting Leading to Code Execution
33RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Nice Talk 0.9.3 - 'tagid' SQL Injection
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component NeoRecruit 1.4 - 'id' SQL Injection
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Domino Web Access Upload Module - 'dwa7w.dll' Remote Buffer Overflow
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RIESGO
abrir ↗Referência
CVE-2017-2478
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir ↗Referência
CVE-2017-2489
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir ↗Referência
CVE-2017-2524
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir ↗Referência
CVE-2017-2800
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting
41RIESGO
abrir ↗Referência
CVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RIESGO
abrir ↗Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir ↗Referência
CVE-2017-3623
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported ve
28RIESGO
abrir ↗Referência
CVE-2017-3881
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.