Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
template creature - SQL Injection / File Disclosure
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
KTP Computer Customer Database CMS 1.0 - Blind SQL Injection
SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Web Mail 4 - Authentication Bypass
SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Price Comparison 4 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
webcp 0.5.7 - 'filelocation' Remote File Disclosure
Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction Pro Platinum - 'seller_id' SQL Injection
SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
BookMarks Favourites Script - 'id' SQL Injection
SQL injection vulnerability in view_group.php in QuidaScript BookMarks Favourites Script (APB) allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection / Local File Inclusion
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
WSN Links Free 4.0.34P - 'comments.php' Blind SQL Injection
SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
WSN Links 2.20 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
AvailScript Article Script - 'view.php' SQL Injection
SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netartmedia Real Estate Portal 1.2 - SQL Injection
SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
LoudBlog 0.8.0a - 'ajax.php' SQL Injection
SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RIESGO
abrir ↗Referência✓ VexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Joomtracker 1.01 - SQL Injection
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
IndexScript 3.0 - 'parent_id' SQL Injection
SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ownbiblio 1.5.3 - 'catid' SQL Injection
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
RaidenFTPd 2.4 build 3620 - Remote Denial of Service
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBB Plugin Custom Pages 1.0 - SQL Injection
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 - Arbitrary Database Backup/Download
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cobalt 0.1 - Multiple SQL Injections
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Harlandscripts Pro Traffic One - 'mypage.php' SQL Injection
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.