Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Hummingbird Deployment Wizard 2008 - Registry Values Creation/Change
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RIESGO
abrir ↗Referência✓ VexDay Proof
Hummingbird 13.0 - ActiveX Remote Buffer Overflow (PoC)
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
1st News - SQL Injection
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Admin Password Changing
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir ↗Referência✓ VexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
BitDefender - Module pdf.xmd Infinite Loop Denial of Service (PoC)
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGu
28RIESGO
abrir ↗Referência✓ VexDay Proof
yahoo answers - 'id' SQL Injection
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RIESGO
abrir ↗Referência✓ VexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-Blog 2.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
User Engine Lite ASP - 'users.mdb' Database Disclosure
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Natterchat 1.12 - Database Disclosure
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
BulletProof FTP Client 2009 - '.bps' Local Buffer Overflow (SEH)
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir ↗Referência✓ VexDay Proof
IntelliTamper 2.07/2.08 - '.map' Local Overwrite (SEH)
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP f
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPired2Quote - Remote Database Disclosure
The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discussion Web 4 - Remote Database Disclosure
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_registration_detailed 4.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RIESGO
abrir ↗Referência✓ VexDay Proof
4Images 1.7.x - 'search.php' SQL Injection
SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche Directory - Database Disclosure
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.