Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
isweb CMS 3.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
mini-pub 0.3 - Local Directory Traversal / File Disclosure
front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a fi
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Office Products - Array Index Bounds Error (PoC)
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of
28RIESGO
abrir ↗Referência✓ VexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
BMForum 5.6 - 'tagname' SQL Injection
SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpscripts Ranking Script - Insecure Cookie Handling
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Noname CMS 1.0 - Multiple SQL Injections
SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discussion Forums 2k 3.3 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir ↗Referência✓ VexDay Proof
Full PHP Emlak Script - 'arsaprint.php' SQL Injection
SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flexphpic 0.0.x - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.
23RIESGO
abrir ↗Referência✓ VexDay Proof
OwenPoll 1.0 - Insecure Cookie Handling
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account na
23RIESGO
abrir ↗Referência✓ VexDay Proof
DeluxeBB 1.2 - Blind SQL Injection
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
ForumApp 3.3 - Remote Database Disclosure
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sepcity Shopping Mall - SQL Injection
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sepcity Lawyer Portal - SQL Injection
SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pixel8 Web Photo Album 3.0 - SQL Injection
SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Kbase 1.0 - SQL Injection
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component RWCards 3.0.11 - Local File Inclusion
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!
43RIESGO
abrir ↗Referência✓ VexDay Proof
SilverSHielD 1.0.2.34 - Denial of Service
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to
23RIESGO
abrir ↗Referência✓ VexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir ↗Referência✓ VexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (2)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0 - 'help_file' Remote Command Execution
Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fast Click 1.1.3/2.3.8 - 'show.php' Remote File Inclusion
PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
IndexScript 3.0 - 'parent_id' SQL Injection
SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ownbiblio 1.5.3 - 'catid' SQL Injection
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
RaidenFTPd 2.4 build 3620 - Remote Denial of Service
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.