Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
Exploit-DB✓ VexDay Proof
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive Realestate Script 3.2 - 'property-list?tbud' SQL Injection
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Freelance Website Script 2.0.6 - 'pr_id' / 'catid' SQL Injection
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php cati
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vanguard 1.4 - SQL Injection
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Readymade Video Sharing Script 3.2 - SQL Injection
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Resume Clone Script 2.0.5 - SQL Injection
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RIESGO
abrir ↗Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Food Order Script 1.0 - 'list?city' SQL Injection
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir ↗Exploit-DB
Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advanced Real Estate Script 4.0.7 - SQL Injection
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yoga Class Script 1.0 - 'list?city' SQL Injection
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.13 (Debian 9) - Local Privilege Escalation
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir ↗Exploit-DB
Linux Kernel - 'mincore()' Heap Page Disclosure (PoC)
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multivendor Penny Auction Clone Script 1.0 - SQL Injection
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive Events & Movie Ticket Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.