Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
22.640 exploits
Referência
CVE-2025-15194
D-Link DIR-600 HTTP Header hedwig.cgi stack-based overflow
48RIESGO
abrir
Referência
CVE-2010-2916
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2010-2916
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2016-1104
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Referência
CVE-2016-1104
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Blog System - SQL Injection
CVE-2008-5311webappsphp
SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2305webappsphp
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, a
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Text Link Sales - 'id' Cross-Site Scripting / SQL Injection
CVE-2008-5486webappsphp
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3234webappsphp
SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
CVE-2008-5654webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
CVE-2008-5930webappsasp
SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Career - SQL Injection
CVE-2008-6867webappsphp
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2010-4866
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2015-1100
The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denia
23RIESGO
abrir
Referência
CVE-2013-1773
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileg
23RIESGO
abrir
Referência
CVE-2012-0906
SQL injection vulnerability in the Moviebase addon for deV!L'z Clanportal (DZCP) 1.5.5 allows remote attackers to execut
23RIESGO
abrir
Referência
CVE-2012-5323
Cross-site request forgery (CSRF) vulnerability in webconfig/admin_passwd/passwd.html/admin_passwd in Xavi X7968 allows
23RIESGO
abrir
Referência
CVE-2022-3241
Build App Online < 1.0.19 - Unauthenticated SQL Injection
48RIESGO
abrir
Referência
CVE-2022-4383
CBX Petition for WordPress <= 1.0.3 - Unauthenticated SQLi
48RIESGO
abrir
Referência
CVE-2017-14956
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/
23RIESGO
abrir
Referência
CVE-2022-4099
Joy Of Text Lite < 2.3.1 - Unauthenticated SQLi
48RIESGO
abrir
ReferênciaVexDay Proof
DigiLeave 1.2 - 'book_id' Blind SQL Injection
CVE-2008-3309webappsasp
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2014-7872
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges
23RIESGO
abrir
Referência
CVE-2014-7872
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges
23RIESGO
abrir
ReferênciaVexDay Proof
ZEELYRICS 2.0 - 'bannerclick.php' SQL Injection
CVE-2008-4717webappsphp
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (1)
CVE-2007-0388webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir
ReferênciaVexDay Proof
BluSky CMS - 'news_id' SQL Injection
CVE-2009-1548webappsphp
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
CVE-2007-1172webappsphp
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Crea-Book 1.0 - Admin Access Bypass / Database Disclosure / Code Execution
CVE-2007-2000webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS module Articles 1.02 - 'print.php?id' SQL Injection
CVE-2007-3311webappsphp
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RIESGO
abrir
anteriorpágina 645 / 755siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.