Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Uploader 1.1 - 'Filename' File Disclosure
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pinnacle Studio 12 - '.hfz' Directory Traversal
InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dokeos 1.6.5 - 'courseLog.php?scormcontopen' SQL Injection
SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Pony Gallery 1.5 - SQL Injection
SQL injection vulnerability in index.php in the Pony Gallery (com_ponygallery) 1.5 and earlier component for Joomla! all
23RIESGO
abrir ↗Referência✓ VexDay Proof
xGB 2.0 - 'xGB.php' Remote Security Bypass
xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP3 - Database Information Disclosure
The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del
23RIESGO
abrir ↗Referência✓ VexDay Proof
DreamNews Manager - 'id' SQL Injection
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeDB 1.1.1 - 'list.php' Local File Inclusion
Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
P2P Foxy - Out of Memory Denial of Service
Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a downlo
23RIESGO
abrir ↗Referência✓ VexDay Proof
MySpeach 2.1b - 'up.php' Remote File Inclusion
PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Multiple incomplete blacklist vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Papoo CMS 3.x - 'pfadhier' Local File Inclusion
Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shop-Script 2.0 - 'index.php' Remote File Disclosure
Directory traversal vulnerability in index.php in Shop-Script 2.0 and possibly other versions allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
MFORUM 0.1a - Arbitrary Add Admin
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
jsite 1.0 oe - SQL Injection / Local File Inclusion
SQL injection vulnerability in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the page param
23RIESGO
abrir ↗Referência✓ VexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniGal b13 - Remote Code Execution
The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
VWar 1.5.0 R15 - 'mvcw.php' Remote File Inclusion
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyRing 4.2.0 - 'view_com.php' SQL Injection
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Ajax Shoutbox 0.0.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Uebimiau Web-Mail 2.7.10/2.7.2 - Remote File Disclosure
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests,
23RIESGO
abrir ↗Referência✓ VexDay Proof
zFeeder 1.6 - 'admin.php' Admin Bypass
zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zix Forum 1.12 - 'layid' SQL Injection
SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
MKPortal 1.1.1 reviews / Gallery modules - SQL Injection
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vanilla 1.1.3 - Blind SQL Injection
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortrol
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Bible Portal Project 2.12 - 'destination' File Inclusion
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scribe 0.2 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Scribe 0.2 allows remote attackers to read arbitrary local files via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent a
23RIESGO
abrir ↗Referência✓ VexDay Proof
AyeView 2.20 - '.GIF' Image Local Crash
AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malfo
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.