Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DBVexDay Proof
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
CVE-2017-17626webappsphp11 dic 2017
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
CVE-2017-17623webappsphp11 dic 2017
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
CVE-2017-17615webappsphp11 dic 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-17622webappsphp11 dic 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-17612webappsphp11 dic 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
CVE-2017-17629webappsphp11 dic 2017
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RIESGO
abrir
Exploit-DBVexDay Proof
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
CVE-2017-17628webappsphp11 dic 2017
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
CVE-2017-17613webappsphp11 dic 2017
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
CVE-2017-17624webappsphp11 dic 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir
Exploit-DBVexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-17619webappsphp11 dic 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanguard 1.4 - SQL Injection
CVE-2017-17873webappsphp11 dic 2017
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RIESGO
abrir
Exploit-DBVexDay Proof
Readymade Video Sharing Script 3.2 - SQL Injection
CVE-2017-17627webappsphp11 dic 2017
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-17641webappsphp11 dic 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
CVE-2017-13861dosmultiple11 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RIESGO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
CVE-2017-1000405doslinux11 dic 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
Exploit-DBVexDay Proof
Food Order Script 1.0 - 'list?city' SQL Injection
CVE-2017-17614webappsphp11 dic 2017
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
CVE-2017-17636webappsphp11 dic 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir
Exploit-DB
Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
CVE-2017-17604webappsphp11 dic 2017
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
CVE-2017-13865dosmacos11 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DBVexDay Proof
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
CVE-2017-17631webappsphp11 dic 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
CVE-2017-17617webappsphp11 dic 2017
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Advanced Real Estate Script 4.0.7 - SQL Injection
CVE-2017-17603webappsphp11 dic 2017
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir
Exploit-DBVexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-17634webappsphp11 dic 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Yoga Class Script 1.0 - 'list?city' SQL Injection
CVE-2017-17630webappsphp11 dic 2017
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
CVE-2017-17635webappsphp11 dic 2017
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Exploit-DB
Linux Kernel 4.13 (Debian 9) - Local Privilege Escalation
CVE-2017-16994locallinux11 dic 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir
Exploit-DB
Linux Kernel - 'mincore()' Heap Page Disclosure (PoC)
CVE-2017-16994doslinux11 dic 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir
Exploit-DBVexDay Proof
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
CVE-2017-17621webappsphp11 dic 2017
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RIESGO
abrir
Exploit-DBVexDay Proof
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
CVE-2017-17620webappsphp11 dic 2017
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-17632webappsphp11 dic 2017
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
anteriorpágina 937 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.