Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module My_eGallery 3.04 - 'gid' SQL Injection
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include
23RIESGO
abrir ↗Referência✓ VexDay Proof
BandSite CMS 1.1.4 - Download Backup / Cross-Site Scripting / Cross-Site Request Forgery
BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain
23RIESGO
abrir ↗Referência✓ VexDay Proof
BandSite CMS 1.1.4 - Download Backup / Cross-Site Scripting / Cross-Site Request Forgery
Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência✓ VexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
WeBid 0.5.4 - 'item.php' SQL Injection
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player < 0.9.6 - '.rt' Local Stack Buffer Overflow
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RIESGO
abrir ↗Referência✓ VexDay Proof
Artmedic CMS 3.4 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
zKup CMS 2.0 < 2.3 - Arbitrary File Upload
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
zKup CMS 2.0 < 2.3 - Remote Add Admin
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Soulseek 157 NS - Remote Buffer Overflow (SEH)
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component jabode - 'id' SQL Injection
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow (PoC)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir ↗Referência✓ VexDay Proof
Cisco Phone 7940 - Remote Denial of Service
Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" response
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RIESGO
abrir ↗Referência✓ VexDay Proof
Lightweight news portal (LNP) 1.0b - Multiple Vulnerabilities
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Facil-CMS 0.1RC - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗Referência✓ VexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir ↗Referência✓ VexDay Proof
OTManager CMS 2.4 - Insecure Cookie Handling
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMI
23RIESGO
abrir ↗Referência✓ VexDay Proof
Half-Life CSTRIKE Server 1.6 - 'no-steam' Denial of Service
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple cr
23RIESGO
abrir ↗Referência✓ VexDay Proof
OneCMS 2.4 - SQL Injection / Upload
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.6 - BODY onload Remote Crash
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (PoC) (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB All Topics Mod 1.5.0 - 'start' SQL Injection
SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.