Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Globsy 1.0 - Remote File Rewriting
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scriptsez Mini Hosting Panel - 'members.php' Local File Inclusion
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
miniPortail 2.2 - Cross-Site Scripting / Local File Inclusion
Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion
Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to inclu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP
23RIESGO
abrir ↗Referência✓ VexDay Proof
Libra PHP File Manager 1.18 - Insecure Cookie Handling
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the
23RIESGO
abrir ↗Referência✓ VexDay Proof
PAD Site Scripts 3.6 - Arbitrary Database Backup
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
VT-Auth 1.0 - 'zHk8dEes3.txt' File Disclosure
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
DaZPHP 0.1 - 'prefixdir' Local File Inclusion
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes
23RIESGO
abrir ↗Referência✓ VexDay Proof
VanGogh Web CMS 0.9 - 'article_ID' SQL Injection
SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Agenda 2.2.4 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include
23RIESGO
abrir ↗Referência✓ VexDay Proof
groone glinks 2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple iOS 4.0.3 - DPAP Server Denial of Service
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (c
23RIESGO
abrir ↗Referência✓ VexDay Proof
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to per
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Brightcode Weblinks - 'catid' SQL Injection
SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Customer 1.3 - Arbitrary Change Admin Password
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Stats Generator 2.1.1 - SQL Injection
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir ↗Referência✓ VexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RIESGO
abrir ↗Referência✓ VexDay Proof
XPOZE Pro 3.06 - 'uid' SQL Injection
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
Rapid Classified 3.1 - Database Disclosure
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RIESGO
abrir ↗Referência✓ VexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remot
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.