Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component 5.2 - ActiveX Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir ↗Referência✓ VexDay Proof
WonderWare SuiteLink 2.0 - Remote Denial of Service (Metasploit)
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, a
28RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earli
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Job Script 2.0 - Arbitrary Change Admin Password
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo
23RIESGO
abrir ↗Referência✓ VexDay Proof
VImpX ActiveX (VImpX.ocx 4.7.3.0) - Remote Buffer Overflow
Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ruby 1.8.6/1.9 (WEBick HTTPd 1.3.1) - Directory Traversal
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when
28RIESGO
abrir ↗Referência✓ VexDay Proof
Angelo-Emlak 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary file
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuickTime 7.4.1 - 'QTPlugin.ocx' Multiple Stack Overflow Vulnerabilities
Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
ActualAnalyzer Lite (free) 2.78 - Local File Inclusion
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to incl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Community Builder 1.0.1 - Blind SQL Injection
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component FlippingBook 1.0.4 - SQL Injection
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RIESGO
abrir ↗Referência✓ VexDay Proof
CUPS 1.3.7 - Cross-Site Request Forgery (Add RSS Subscription) Remote Crash
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon
23RIESGO
abrir ↗Referência✓ VexDay Proof
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPThai.Net Forum 8.5 - Remote Database Disclosure
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.