Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
compteur 2.0 - 'param_editor.php' Remote File Inclusion
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RIESGO
abrir ↗Referência✓ VexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
emuCMS 0.3 - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hedgehog-CMS 1.21 - 'header.php' Local File Inclusion
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Webhost Billing System (AWBS) 2.7.1 - 'news.php' SQL Injection
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
PayProCart 1146078425 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Denial of Service
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RIESGO
abrir ↗Referência✓ VexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBLASTER CMS 1.0 RC1 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals
23RIESGO
abrir ↗Referência✓ VexDay Proof
KVIrc 3.4.2 Shiny - URI handler Remote Command Execution
Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Extcalendar 2 - 'profile.php' Remote User Pass Change
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without prov
23RIESGO
abrir ↗Referência✓ VexDay Proof
study planner (studiewijzer) 0.15 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globa
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dana IRC 1.3 - Remote Buffer Overflow (PoC)
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
SCart 2.0 - 'page' Remote Code Execution
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RIESGO
abrir ↗Referência✓ VexDay Proof
ViRC 2.0 - JOIN Response Remote Overwrite (SEH)
Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long resp
23RIESGO
abrir ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Demo4 CMS - 'id' SQL Injection
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component FacileForms 1.4.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 fo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_loudmouth 4.0j - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and p
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.