Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
miniBloggie 1.0 - 'del.php' Blind SQL Injection
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Catviz 0.4.0 beta1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
pSys 0.7.0 Alpha - 'chatbox.php' SQL Injection
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (1)
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (2)
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Triton CMS Pro 1.06 - 'x-forwarded-for' Blind SQL Injection
SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwar
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS WebBlizzard - 'index.php' Blind SQL Injection
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - Remote Command Execution
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RIESGO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir ↗Referência✓ VexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RIESGO
abrir ↗Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' Local Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.5.1 (Windows) - 'blogpost' Local File Inclusion
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.2.2 - '/pages_data.php' Arbitrary Edit/Add/Delete
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Amaya Web Editor 11.0 - XML / HTML Parser
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RIESGO
abrir ↗Referência✓ VexDay Proof
Simple DNS Plus 5.0/4.1 - Remote Denial of Service
Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of servic
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP1 - Remote Code Execution
Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP
23RIESGO
abrir ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RIESGO
abrir ↗Referência✓ VexDay Proof
PPMate PPMedia Class - ActiveX Control Buffer Overflow (PoC)
Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attack
28RIESGO
abrir ↗Referência✓ VexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (1)
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.