Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Binn SBuilder - 'nid' Blind SQL Injection
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
TutorialCMS 1.02 - 'Username' SQL Injection
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disa
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Photo Gallery 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
FaScript FaPersianHack 1.0 - SQL Injection
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MCQuiz 0.9 Final - 'tid' SQL Injection
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component paxxgallery 0.2 - 'iid' SQL Injection
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Thecus N5200Pro NAS Server Control Panel - Remote File Inclusion
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component Ricette 1.0 - SQL Injection
SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board 3.0.x - Blind SQL Injection
SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Classifieds - 'cid' SQL Injection
SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
eXchange POP3 5.0.050203 - RPCT TO Remote Buffer Overflow
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execu
35RIESGO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RIESGO
abrir ↗Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RIESGO
abrir ↗Referência✓ VexDay Proof
eazyPortal 1.0 - 'cookie' SQL Injection
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuickTalk Forum 1.6 - Blind SQL Injection
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.2.1 - 'X-Forwarded-For' HTTP Header Blind SQL Injection
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
eXV2 Module Viso 2.0.4.3 - 'kid' SQL Injection
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiveCart 1.1.1 - 'id' Blind SQL Injection
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP Module ConcoursPhoto 2.0 - 'C_ID' SQL Injection
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mole Group Last Minute Script 4.0 - SQL Injection
SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Catviz 0.4.0 beta1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RIESGO
abrir ↗Referência✓ VexDay Proof
pPIM 1.0 - Upload/Change Password
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir ↗Referência✓ VexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Article Publisher PRO - 'userid' SQL Injection
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.