Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.207exploits catalogados
36.419CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 23.022GitHub PoC 15.023VulnCheck XDB 8846Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Brim 1.2.1 - 'renderer' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
HispaH textlinksads - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPPowerCards 2.10 - 'txt.inc.php' Remote Code Execution
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is
23RIESGO
abrir ↗Referência✓ VexDay Proof
ALiCE-CMS 0.1 - 'CONFIG[local_root]' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
AdMan 1.1.20070907 - 'campaignId' SQL Injection
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bux.to Clone Script - Insecure Cookie Handling
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the logge
23RIESGO
abrir ↗Referência✓ VexDay Proof
P-News 1.16 - Remote File Inclusion
PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
SuperNET Shop 1.0 - SQL Injection
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
JaxUltraBB 2.0 - 'delete.php' Remote Auto Deface
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZ-Ticket 0.0.1 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free Directory Script 1.1.1 - 'API_HOME_DIR' Remote File Inclusion
PHP remote file inclusion vulnerability in init.php in Free Directory Script 1.1.1, when register_globals is enabled, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
E-topbiz Link Back Checker 1 - Insecure Cookie Handling
E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir ↗Referência✓ VexDay Proof
E Annu 1.0 - Authentication Bypass / SQL Injection
SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
PunBB (Private Messaging System 1.2.x) - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
CFMBLOG - 'categorynbr' Blind SQL Injection
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
CF_Auction - Blind SQL Injection
SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
CF_Forum - Blind SQL Injection
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
ProQuiz 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Job Board - Authentication Bypass
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyTopix 1.3.0 - SQL Injection
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
RSS Simple News - SQL Injection
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
PostNuke 0.763 - 'PNSV lang' Remote Code Execution
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gallery MX 2.0.0 - Blind SQL Injection
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.1.4 - SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' Blind SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.