Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2026-9377
SourceCodester SUP Online Shopping productedit.php cross site scripting
33RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
CVE-2008-6197webappsphp
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
MyBB Plugin Custom Pages 1.0 - SQL Injection
CVE-2008-6198webappsphp
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
2532/Gigs 1.2.2 - Arbitrary Database Backup/Download
CVE-2008-6199webappsphp
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via
23RIESGO
abrir
Referência
glibc 2.38 - Buffer Overflow
CVE-2023-4911HIGHbajo ataquelocallinux
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
ReferênciaVexDay Proof
Cobalt 0.1 - Multiple SQL Injections
CVE-2008-6202webappsasp
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir
Referência
CVE-2019-10068
CVE-2019-10068CRITICALbajo ataque
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RIESGO
abrir
Referência
CVE-2026-7228
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
CVE-2008-6215webappsphp
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels
23RIESGO
abrir
Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RIESGO
abrir
ReferênciaVexDay Proof
Simple Document Management System 1.1.4 - Authentication Bypass
CVE-2008-6220webappsphp
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earli
23RIESGO
abrir
Referência
CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
Referência
CVE-2020-5847
CVE-2020-5847CRITICALbajo ataque
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir
ReferênciaVexDay Proof
PHP Auto Listings - 'pg' SQL Injection
CVE-2008-6226webappsphp
SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled,
23RIESGO
abrir
Referência
CVE-2019-7609
CVE-2019-7609CRITICALbajo ataque
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Webstore - 'where' SQL Injection
CVE-2008-6242webappsphp
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Gaming Cheats - SQL Injection
CVE-2008-6244webappsphp
SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2023-24788
NotrinosERP v0.7 was discovered to contain a SQL injection vulnerability via the OrderNumber parameter at /NotrinosERP/s
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Top Sites - SQL Injection
CVE-2008-6247webappsphp
SQL injection vulnerability in topsite.php in Scripts For Sites (SFS) EZ Top Sites allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Galatolo Web Manager 1.3a - Cross-Site Scripting / SQL Injection
CVE-2008-6249webappsphp
SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
smcFanControl 2.1.2 (OSX) - Multiple Buffer Overflow Vulnerabilities (PoC)
CVE-2008-6252dososx
Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and g
23RIESGO
abrir
Referência
CVE-2026-17434
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
33RIESGO
abrir
Referência
CVE-2026-65711
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
41RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6350webappsphp
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6351webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to in
23RIESGO
abrir
ReferênciaVexDay Proof
Xpoze 4.10 - 'menu' Blind SQL Injection
CVE-2008-6352webappsphp
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
CVE-2008-6355webappsasp
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
MyCal Personal Events Calendar - Database Disclosure
CVE-2008-6357webappsasp
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
anteriorpágina 503 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.