Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Winamp 5.541 - '.mp3'/'.aiff' File Multiple Denial of Service Vulnerabilities
Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly e
28RIESGO
abrir ↗Referência✓ VexDay Proof
The Walking Club - Authentication Bypass
SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flax Article Manager 1.1 - 'cat_id' SQL Injection
SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenGoo 1.1 - Local File Inclusion
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RIESGO
abrir ↗Referência✓ VexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RIESGO
abrir ↗Referência✓ VexDay Proof
Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RIESGO
abrir ↗Referência✓ VexDay Proof
BibCiter 1.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Motorola Wimax modem CPEi300 - File Disclosure / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated user
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netartmedia Car Portal 1.0 - Authentication Bypass
SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartSiteCMS 1.0 - Blind SQL Injection
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpList 2.10.8 - Local File Inclusion
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is dis
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Photo Album 0.8b - 'preview' Local File Inclusion
Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Euphonics Audio Player 1.0 (Windows XP SP3) - '.pls' Local Buffer Overflow
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RIESGO
abrir ↗Referência✓ VexDay Proof
Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service v
45RIESGO
abrir ↗Referência✓ VexDay Proof
Audacity 1.2.6 - '.gro' Local Buffer Overflow (PoC)
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacit
28RIESGO
abrir ↗Referência✓ VexDay Proof
ItCMS 2.1a - Authentication Bypass
SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Portfol 1.2 - 'vcatid' SQL Injection
SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Realtor 747 - 'define.php?INC_DIR' Remote File Inclusion
PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
webframe 0.76 - Multiple File Inclusions
Multiple PHP remote file inclusion vulnerabilities in WebFrame 0.76 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject a
23RIESGO
abrir ↗Referência✓ VexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
IF-CMS 2.0 - 'id' Blind SQL Injection
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to i
23RIESGO
abrir ↗Referência✓ VexDay Proof
A Better Member-Based ASP Photo Gallery - 'entry' SQL Injection
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote atta
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.