Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2026-16981
DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
33RIESGO
abrir
Referência
CVE-2026-16968
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
33RIESGO
abrir
Referência
CVE-2015-4027
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RIESGO
abrir
ReferênciaVexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
CVE-2007-3098doswindows
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RIESGO
abrir
ReferênciaVexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
CVE-2007-3103locallinux
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RIESGO
abrir
ReferênciaVexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
CVE-2007-3118webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Kartli Alisveris Sistemi 1.0 - SQL Injection
CVE-2007-3119webappsasp
SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3138webappsphp
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RIESGO
abrir
Referência
CVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3139webappsphp
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow (2)
CVE-2007-3148remotewindows
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
28RIESGO
abrir
ReferênciaVexDay Proof
QuickTicket 1.2 - 'qti_checkname.php' Local File Inclusion
CVE-2007-3547webappsphp
Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute
23RIESGO
abrir
Referência
CVE-2017-17632
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Buddy Zone 1.5 - 'view_sub_cat.php?cat_id' SQL Injection
CVE-2007-3549webappsphp
SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
WebChat 0.78 - 'login.php?rid' SQL Injection
CVE-2007-3534webappsphp
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
b1gbb 2.24.0 - SQL Injection / Cross-Site Scripting
CVE-2007-3589webappsphp
Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3607doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3608doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3608doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir
Referência
CVE-2017-17634
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Referência
CVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Referência
CVE-2017-17636
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir
Referência
CVE-2026-58053
Gitea act_runner - Container Hardening Bypass via Workflow Container Options
48RIESGO
abrir
Referência
CVE-2026-58052
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
33RIESGO
abrir
ReferênciaVexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
CVE-2007-3840webappsphp
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2019-25761
Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id
41RIESGO
abrir
Referência
CVE-2017-17637
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Pictures Rating - 'index.php?msgid' SQL Injection
CVE-2007-3881webappsphp
SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrar
23RIESGO
abrir
anteriorpágina 468 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.