Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to de
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir ↗Referência✓ VexDay Proof
Michelles L2J Dropcalc 4 - SQL Injection
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users t
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB ezBoard Converter 0.2 - 'ezconvert_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB++ Build 100 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RIESGO
abrir ↗Referência✓ VexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RIESGO
abrir ↗Referência✓ VexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RIESGO
abrir ↗Referência✓ VexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RIESGO
abrir ↗Referência✓ VexDay Proof
NewzCrawler 1.8 - invalid string Remote Denial of Service
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RIESGO
abrir ↗Referência✓ VexDay Proof
FrontAccounting 1.12 build 31 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execut
45RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Nice Talk 0.9.3 - 'tagid' SQL Injection
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component NeoRecruit 1.4 - 'id' SQL Injection
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
SunShop Shopping Cart 4.0 RC 6 - 'Search' Blind SQL Injection
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
NuclearBB Alpha 2 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e
35RIESGO
abrir ↗Referência✓ VexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.0 sondages Module - SQL Injection
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
MW6 Technologies QRCode ActiveX 3.0 - Remote File Overwrite
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Techn
28RIESGO
abrir ↗Referência✓ VexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RIESGO
abrir ↗Referência✓ VexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RIESGO
abrir ↗Referência✓ VexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
jPORTAL 2.3.1 - 'articles.php' SQL Injection
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmallNuke 2.0.4 - Pass Recovery SQL Injection
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xforum 1.4 - 'topic' SQL Injection
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.