Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
ABG Blocking Script 1.0a - 'abg_path' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RIESGO
abrir ↗Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
pPIM 1.0 - Upload/Change Password
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
ilchClan 1.05g - 'tid' SQL Injection
SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Orca 2.0/2.0.2 - 'params.php?gConf[dir][layouts]' Remote File Inclusion
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cheats Complete Website 1.1.1 - 'itemID' SQL Injection
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
SebracCMS 0.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
AcmlmBoard 1.A2 - 'pow' SQL Injection
SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction 6.2.1 - 'classifide_ad.php' SQL Injection
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Invision Power Board 2.1.4 - Register Users Denial of Service
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp
23RIESGO
abrir ↗Referência✓ VexDay Proof
FAQ Manager 1.2 - 'categorie.php' SQL Injection
SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to in
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoGirls BiZ - Blind SQL Injection
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebStudio eCatalogue - Blind SQL Injection
SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cold BBS - Remote Database Disclosure
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir ↗Referência✓ VexDay Proof
Active Trade 2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS little 0.0.1 - 'term' SQL Injection
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Turnkey Arcade Script - SQL Injection (1)
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Authentication Bypass
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
DELTAScripts PHP Classifieds 7.5 - SQL Injection
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPAlumni - SQL Injection
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
eDContainer 2.22 - Local File Inclusion
Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
VP-ASP Shopping Cart 6.50 - Database Disclosure
VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.