Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência✓ VexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Referência✓ VexDay Proof
AJA Portal 1.2 (Windows) - Local File Inclusion
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗Referência✓ VexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
WholeHogSoftware Password Protect - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'base_include.php' Remote File Inclusion
PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClickCart 6.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2
23RIESGO
abrir ↗Referência✓ VexDay Proof
Open Meetings Filing Application - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RIESGO
abrir ↗Referência✓ VexDay Proof
Amaya 11.1 - W3C Editor/Browser (defer) Stack Overflow (PoC)
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script
28RIESGO
abrir ↗Referência
CVE-2009-4680
SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2014-8322
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RIESGO
abrir ↗Referência
CVE-2014-8356
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RIESGO
abrir ↗Referência
CVE-2014-8356
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RIESGO
abrir ↗Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RIESGO
abrir ↗Referência
CVE-2014-8357
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RIESGO
abrir ↗Referência
CVE-2014-8361
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RIESGO
abrir ↗Referência
CVE-2014-8375
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ
23RIESGO
abrir ↗Referência
CVE-2014-8386
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RIESGO
abrir ↗Referência
CVE-2014-8826
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RIESGO
abrir ↗Referência
CVE-2014-8953
Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to
23RIESGO
abrir ↗Referência
CVE-2014-8953
Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to
23RIESGO
abrir ↗Referência
CVE-2014-8997
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al
23RIESGO
abrir ↗Referência
CVE-2014-9095
Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência
CVE-2014-9097
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RIESGO
abrir ↗Referência
CVE-2014-9144
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.