Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.624 exploits
Referência✓ VexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir ↗Referência
CVE-2010-0631
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow
23RIESGO
abrir ↗Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RIESGO
abrir ↗Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RIESGO
abrir ↗Referência
CVE-2010-0642
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RIESGO
abrir ↗Referência
CVE-2021-25160
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
23RIESGO
abrir ↗Referência✓ VexDay Proof
0irc-client 1345 build20060823 - Denial of Service
0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se
23RIESGO
abrir ↗Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência
CVE-2020-11700
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RIESGO
abrir ↗Referência✓ VexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RIESGO
abrir ↗Referência
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RIESGO
abrir ↗Referência
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RIESGO
abrir ↗Referência
CVE-2015-2315
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RIESGO
abrir ↗Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that tri
23RIESGO
abrir ↗Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir ↗Referência
CVE-2010-0672
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2014-4688
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir ↗Referência
CVE-2011-4810
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RIESGO
abrir ↗Referência✓ VexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Frequency Clock 0.1b - 'securelib' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RIESGO
abrir ↗Referência
CVE-2013-6366
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod
23RIESGO
abrir ↗Referência
CVE-2016-7851
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne
23RIESGO
abrir ↗Referência
CVE-2017-9147
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau
23RIESGO
abrir ↗Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.