Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
PhpCommander 3.0 - 'upload' Remote Code Execution
Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'class.mysql.php' Remote File Inclusion
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyPicGallery 1.0 - Arbitrary Add Admin
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting
23RIESGO
abrir ↗Referência✓ VexDay Proof
odars CMS 1.0.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vivvo Article Manager 3.2 - 'id' SQL Injection
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Stash 1.0.3 - Insecure Cookie Handling
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by settin
23RIESGO
abrir ↗Referência✓ VexDay Proof
Atomic Photo Album 1.1.0pre4 - Insecure Cookie Handling
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which proba
23RIESGO
abrir ↗Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Insecure Cookie Handling
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the
23RIESGO
abrir ↗Referência✓ VexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗Referência✓ VexDay Proof
A+ PHP Scripts - Nms Insecure Cookie Handling
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator priv
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
Esqlanelapse Software Project 2.6.2 - Insecure Cookie Handling
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enomb
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPG.Board 0.0.8Beta2 - Insecure Cookie Handling
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep
23RIESGO
abrir ↗Referência✓ VexDay Proof
FretsWeb 1.2 - 'name' Blind SQL Injection
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - 'teams.php' SQL Injection
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Calendar Script 1.1 - Insecure Cookie Handling
Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPAuctionSystem - Insecure Cookie Handling
PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via m
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component EXP Shop - 'catid' SQL Injection
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir ↗Referência✓ VexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Referência✓ VexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.