Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Limbo CMS 1.0.4.2 - 'catid' SQL Injection
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS 2.0.13.2 - 'xoopsOption[nocommon]' Remote Command Execution
mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite varia
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpListPro 2.0.1 - 'Language' Remote Code Execution
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, a
23RIESGO
abrir ↗Referência✓ VexDay Proof
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newspo
28RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board 2.3.5 - 'links.php' SQL Injection
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Student Study Center Management System v1.0 - Stored Cross-Site Scripting (XSS)
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RIESGO
abrir ↗Referência✓ VexDay Proof
Service Provider Management System v1.0 - SQL Injection
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RIESGO
abrir ↗Referência✓ VexDay Proof
WU-FTPD 2.6.2 - 'wuftpd-freezer.c' Remote Denial of Service
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, w
23RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir ↗Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb ePhotos 1.0 - 'subLevel2.asp' SQL Injection
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
blur6ex 0.3.462 - 'ID' Admin Disclosure / Blind SQL Injection
SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Micro CMS 0.3.5 - 'microcms_path' Remote File Inclusion
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
BandSite CMS 1.1.1 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, al
28RIESGO
abrir ↗Referência✓ VexDay Proof
MagNet BeeHive CMS (header) - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, a
28RIESGO
abrir ↗Referência✓ VexDay Proof
THoRCMS 1.3.1 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
28RIESGO
abrir ↗Referência✓ VexDay Proof
Pheap CMS 1.1 - 'lpref' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-revista 1.1.2 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
SL_Site 1.0 - 'spaw_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RIESGO
abrir ↗Referência✓ VexDay Proof
PhotoKorn Gallery 1.52 - 'dir_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execu
28RIESGO
abrir ↗Referência✓ VexDay Proof
Fantastic News 2.1.4 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
TIBCO Rendezvous 7.4.11 - Password Extractor
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to
23RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Director < 5.10 - 'Redirect.bat' Directory Traversal
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vivvo Article Manager 3.2 - 'classified_path' File Inclusion
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fire Soft Board RC 3 - 'racine' Remote File Inclusion
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Web Server Creator 0.1 - 'l' Remote File Inclusion
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.