Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗Referência✓ VexDay Proof
evCal Events Calendar - Database Disclosure
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyCal Personal Events Calendar - Database Disclosure
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Social Groupie - 'id' SQL Injection
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Referência✓ VexDay Proof
CHILKAT ASP String - 'CkString.dll 1.1 SaveToFile()' Insecure Method
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String
23RIESGO
abrir ↗Referência✓ VexDay Proof
Banner Exchange Java - Authentication Bypass
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ad Management Java - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Codefixer MailingListPro - Database Disclosure
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Multi SEO phpBB 1.1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Feindt Computerservice News 2.0 - 'newsadmin.php?action' Remote File Inclusion
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote
35RIESGO
abrir ↗Referência✓ VexDay Proof
LimeSurvey (phpsurveyor) 1.49rc2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to exe
35RIESGO
abrir ↗Referência✓ VexDay Proof
HotScripts Clone - 'cid' SQL Injection
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft DXMedia SDK 6 - 'SourceUrl' ActiveX Remote Code Execution
Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX cont
35RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction Pro Platinum Skin - 'item_id' SQL Injection
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RIESGO
abrir ↗Referência✓ VexDay Proof
SOTEeSKLEP 3.5RC9 - 'file' Remote File Disclosure
Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Referência✓ VexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗Referência✓ VexDay Proof
HiveMaker Professional 1.0.2 - 'cid' SQL Injection
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗Referência✓ VexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Buffer Overflow (2)
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.