Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Easy News Content Management - Database Disclosure
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP User Engine .NET - Remote Database Disclosure
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebFileExplorer 3.1 - 'db.mdb' Database Disclosure
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin
23RIESGO
abrir ↗Referência✓ VexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pro Chat Rooms 3.0.2 - Cross-Site Scripting / Cross-Site Request Forgery
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local
23RIESGO
abrir ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RIESGO
abrir ↗Referência✓ VexDay Proof
iDB 0.2.5pa SVN 243 - 'skin' Local File Inclusion
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RIESGO
abrir ↗Referência✓ VexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RIESGO
abrir ↗Referência✓ VexDay Proof
BosClassifieds - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RIESGO
abrir ↗Referência✓ VexDay Proof
PayPal eStore - Admin Password Change
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RIESGO
abrir ↗Referência✓ VexDay Proof
Destar 0.2.2-5 - Arbitrary Add Admin
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Joomlaradio 5.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f
35RIESGO
abrir ↗Referência✓ VexDay Proof
Roundcube Webmail 0.2-3 Beta - Code Execution
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - '.chm' Denial of Service (HTML Compiled)
Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and
35RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft Ajax Portal 3.0 - 'page' SQL Injection
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
SimpCMS - 'keyword' SQL Injection
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the ke
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.0 Member_Space Module - SQL Injection
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.