Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RIESGO
abrir ↗Referência✓ VexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
TikiWiki 1.9.8 - Remote PHP Injection
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RIESGO
abrir ↗Referência✓ VexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RIESGO
abrir ↗Referência✓ VexDay Proof
AvailScript Article Script - Arbitrary File Upload
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RIESGO
abrir ↗Referência✓ VexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Mo
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPStore Complete Classifieds Script - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPStore PHP Job Search Script - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
eXtremail 2.1.1 - PLAIN Authentication Remote Stack Overflow
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending
28RIESGO
abrir ↗Referência✓ VexDay Proof
eXtremail 2.1.1 - 'memmove()' Remote Denial of Service
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execu
28RIESGO
abrir ↗Referência✓ VexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir ↗Referência✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code b
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bankoi Webhost Panel 1.20 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
ooVoo 1.7.1.35 - 'URL Protocol' Remote Unicode Buffer Overflow (PoC)
Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0.5 - Authentication Bypass
SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - 'SaveAs' Remote Buffer Overflow
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.14
28RIESGO
abrir ↗Referência✓ VexDay Proof
The Rat CMS Alpha 2 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chilkat IMAP ActiveX 7.9 - File Execution / Denial of Service
Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.Chilkat
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.