Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wma' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RIESGO
abrir ↗Referência✓ VexDay Proof
RhinoSoft Serv-U FTP Server 7.4.0.1 - 'MKD' Create Arbitrary Directories
Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP iCalendar 2.21 - 'publish.ical.php' Remote Code Execution
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP iCalendar 2.21 - 'cookie' Remote Code Execution
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to in
23RIESGO
abrir ↗Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RIESGO
abrir ↗Referência✓ VexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shop Script Pro 2.12 - SQL Injection
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
yogurt 0.3 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authentic
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPortal 1 - 'topicler.php?id' SQL Injection
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Jumi - 'fileid' Blind SQL Injection
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authen
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpWebThings 1.5.2 - MD5 Hash Retrieve/File Disclosure
SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBookingCalendar 1.0c - 'details_view.php' SQL Injection
SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RIESGO
abrir ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Monster Top List 1.4.2 - 'functions.php?root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sphider 1.3 - 'configset.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disa
23RIESGO
abrir ↗Referência✓ VexDay Proof
OCE 3121/3122 Printer - 'parser.exe' Denial of Service
parser.exe in Océ (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a l
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
53RIESGO
abrir ↗Referência✓ VexDay Proof
ACal 2.2.6 - 'day.php' Remote File Inclusion
PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.