Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Pre Classified Listings - Insecure Cookie Handling
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pre Shopping Mall - Insecure Cookie Handling
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Struts 2.0.11 - Multiple Directory Traversal Vulnerabilities
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote at
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vibro-CMS - Multiple SQL Injections
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WEBBDOMAIN WebShop 1.02 - SQL Injection / Cross-Site Scripting
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DHCart 3.84 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
firmCHANNEL Indoor & Outdoor Digital Signage 3.24 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Document Management System 1.1.4 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
nicLOR Puglia Landscape - Local File Inclusion
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XWork < 2.0.11.2 - 'ParameterInterceptor' Class OGNL Security Bypass
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and othe
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lynx 2.8 - '.mailcap'/'.mime.type' Local Code Execution
Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acc Statistics 1.1 - Insecure Cookie Handling
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acc Statistics 1.1 - Insecure Cookie Handling
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pppBlog 0.3.11 - File Disclosure
Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Downline Builder Pro - 'tr.php' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher Pro 1.5 - Insecure Cookie Handling
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GE Fanuc Real Time Information Portal 2.6 - 'writeFile()' API (Metasploit)
Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote at
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Short Url & Url Tracker - SQL Injection
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arb
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.