Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free Image Hosting 1.0 - 'forgot_pass.php' File Inclusion
PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RIESGO
abrir ↗Referência✓ VexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RIESGO
abrir ↗Referência✓ VexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpDynaSite 3.2.2 - 'racine' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Article System 0.6 - 'volume.php' Remote File Inclusion
PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Drake CMS < 0.2.3 ALPHA rev.916 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeWebShop.org script 2.2.2 - Multiple Vulnerabilities
Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Creasito E-Commerce Content Manager - 'admin' Authentication Bypass
Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged funct
23RIESGO
abrir ↗Referência✓ VexDay Proof
Omni-NFS Server 5.2 - 'nfsd.exe' Remote Stack Overflow (Metasploit)
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RIESGO
abrir ↗Referência✓ VexDay Proof
SAP Web Application Server 6.40 - Arbitrary File Disclosure
Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 a
23RIESGO
abrir ↗Referência✓ VexDay Proof
iPrimal Forums - '/admin/index.php' Change User Password
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwo
23RIESGO
abrir ↗Referência✓ VexDay Proof
iPrimal Forums - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenEMR 2.8.1 - 'srcdir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Soholaunch Pro 4.9 r36 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quick.CMS.Lite 0.3 - Cookie sLanguage Local File Inclusion
Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include a
23RIESGO
abrir ↗Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Smiley 1.0 - 'default.asp' Authentication Bypass / SQL Injection
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hpecs Shopping Cart - Remote Authentication Bypass
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
WORK System E-Commerce 3.0.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other ver
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'editor.php' Remote File Inclusion
PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 and earlier, when register_globals is e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Etomite CMS 0.6.1.2 - '/manager/index.php' Local File Inclusion
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MosReporter 0.9.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and
23RIESGO
abrir ↗Referência✓ VexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.