Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir ↗Referência✓ VexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RIESGO
abrir ↗Referência✓ VexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyForum 1.3 - Insecure Cookie Handling
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Membership System 1.3 - Authentication Bypass
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Agares ThemeSiteScript 1.0 - 'loadadminpage' Remote File Inclusion
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
PromoteWeb MySQL - 'id' SQL Injection
SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pro Chat Rooms 3.0.3 - SQL Injection
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yoxel 1.23beta - 'itpm_estimate.php' Remote Code Execution
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated us
23RIESGO
abrir ↗Referência✓ VexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
SePortal 2.4 - 'poll_id' SQL Injection
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod Kroax 4.42 - 'category' SQL Injection
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Article 1.0 - 'featured_article.php' SQL Injection
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to
28RIESGO
abrir ↗Referência✓ VexDay Proof
Experts 1.0.0 - 'answer.php' SQL Injection
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPPortal Free Version - 'Topic_Id' SQL Injection
SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
pSys 0.7.0.a - 'shownews' SQL Injection
SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yuhhu 2008 SuperStar - 'board' SQL Injection
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Professional Download Assistant 0.1 - Authentication Bypass
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RIESGO
abrir ↗Referência✓ VexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nukedit 4.9.x - Remote Create Admin
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
lcxbbportal 0.1 alpha 2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
QMail Mailing List Manager 1.2 - Database Disclosure
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JMovies 1.1 - 'id' SQL Injection
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP AutoDealer - Remote Database Disclosure
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.