Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
Referência
CVE-2026-12273
Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Auto-Approved Comment Creation
33RIESGO
abrir
Referência
CVE-2026-12271
Tutor LMS < 3.9.13 - Subscriber+ Arbitrary Quiz Attempt Modification via IDOR
33RIESGO
abrir
Referência
CVE-2026-15528
lamaalrajih kicad-mcp path_validator.py protection mechanism
33RIESGO
abrir
Referência
CVE-2026-15514
Metasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
CVE-2007-2940webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RIESGO
abrir
Referência
CVE-2017-17600
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
CVE-2007-2941webappsphp
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RIESGO
abrir
Referência
CVE-2017-17600
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
CVE-2007-2947webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
wanewsletter 2.1.3 - Remote File Inclusion
CVE-2007-2969webappsphp
PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to e
35RIESGO
abrir
Referência
CVE-2026-12775
Montodel House-Rental-Management login.php sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module icontent 1.0/4.5 - Remote File Inclusion
CVE-2007-3057webappsphp
PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS a
35RIESGO
abrir
Referência
CVE-2019-25752
Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection
41RIESGO
abrir
Referência
CVE-2015-2426
CVE-2015-2426HIGHbajo ataque
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir
Referência
CVE-2020-37252
Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20091
Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2016-20090
Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service Path
41RIESGO
abrir
Referência
CVE-2026-55200
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
48RIESGO
abrir
Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir
Referência
CVE-2026-12193
VS Revo RevoUninstaller IOCTL RevoDetector.sys IOCtl_Handler heap-based overflow
41RIESGO
abrir
Referência
CVE-2026-12188
Grit42 Grit GritEntityController grit_entity_controller.rb sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
Particle Gallery 1.0.1 - SQL Injection
CVE-2007-3065webappsphp
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2017-17603
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir
ReferênciaVexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
CVE-2007-3068localwindows
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RIESGO
abrir
Referência
CVE-2026-18927
imranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-15360
Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args
48RIESGO
abrir
Referência
CVE-2026-15210
Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute Force
48RIESGO
abrir
Referência
CVE-2026-15230
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
41RIESGO
abrir
Referência
CVE-2026-14553
Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
41RIESGO
abrir
Referência
CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
28RIESGO
abrir
anteriorpágina 514 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.