Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Flexphplink Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RIESGO
abrir ↗Referência✓ VexDay Proof
Megacubo 5.0.7 - 'mega://' Remote 'eval()' Injection
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Affiliate - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
SAPID CMF Build 87 - 'last_module' Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'directory.php' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Home Business Directory - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers
28RIESGO
abrir ↗Referência✓ VexDay Proof
Lizardware CMS 0.6.0 - Blind SQL Injection
SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xitami Web Server 2.5 - 'If-Modified-Since' Remote Buffer Overflow
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RIESGO
abrir ↗Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vibro-School-CMS - 'nID' SQL Injection
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
helplink 0.1.0 - 'show.php' Remote File Inclusion
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute a
35RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Authentication Bypass
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Softbiz Classifieds PLUS - 'id' SQL Injection
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RIESGO
abrir ↗Referência✓ VexDay Proof
7Shop 1.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RIESGO
abrir ↗Referência✓ VexDay Proof
C6 Messenger - ActiveX Remote Download and Execute
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force
50RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.