Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.581 exploits
Referência✓ VexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
netForo! 0.1 - 'down.php?file_to_download' Remote File Disclosure
Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpsyncml 0.1.2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
mutiple timesheets 5.0 - Multiple Vulnerabilities
Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Velocity Web-Server 1.0 - Directory Traversal
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gravy Media Photo Host 1.0.8 - Local File Disclosure
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to re
23RIESGO
abrir ↗Referência
CVE-2013-2945
SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to
23RIESGO
abrir ↗Referência
CVE-2015-2701
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RIESGO
abrir ↗Referência
CVE-2012-1200
Multiple PHP remote file inclusion vulnerabilities in Nova CMS allow remote attackers to execute arbitrary PHP code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyDirectory 10.4.4 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2017-5264
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
23RIESGO
abrir ↗Referência
CVE-2012-2442
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência
CVE-2012-2442
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência
CVE-2019-14346
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RIESGO
abrir ↗Referência
CVE-2009-3912
Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Referência
CVE-2009-4434
Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbi
23RIESGO
abrir ↗Referência
CVE-2009-4434
Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbi
23RIESGO
abrir ↗Referência
CVE-2009-3123
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebCreator 0.2.6-rc3 - 'moddir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
PowerBook 1.21 - 'index.php' Local File Inclusion
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Multi-Page Comment System 1.1.0 - Insecure Cookie Handling
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain priv
23RIESGO
abrir ↗Referência✓ VexDay Proof
AyeView 2.20 - Invalid Bitmap Header Parsing Crash
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a
23RIESGO
abrir ↗Referência
CVE-2012-1047
Directory traversal vulnerability in the WWWHELP Service (js/html/wwhelp.htm) in Cyberoam Central Console (CCC) 2.00.2 a
23RIESGO
abrir ↗Referência
CVE-2010-2330
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (c
28RIESGO
abrir ↗Referência
CVE-2013-6787
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlie
23RIESGO
abrir ↗Referência
CVE-2010-2333
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scrip
50RIESGO
abrir ↗Referência
CVE-2018-0822
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an eleva
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.