Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Post 1.0 - Cookie Modification Privilege Escalation
PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass secu
28RIESGO
abrir ↗Referência✓ VexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Leap CMS 0.1.4 - SQL Injection / Cross-Site Scripting / Arbitrary File Upload
Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading
23RIESGO
abrir ↗Referência✓ VexDay Proof
Teraway FileStream 1.0 - Insecure Cookie Handling
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw
23RIESGO
abrir ↗Referência✓ VexDay Proof
Total Video Player 1.03 - '.m3u' File Local Buffer Overflow
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RIESGO
abrir ↗Referência✓ VexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Heap Overflow (PoC)
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (1)
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.asx HREF' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPBB2 MODificat 0.2.0 - 'functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote at
28RIESGO
abrir ↗Referência✓ VexDay Proof
FaScript FaPersian Petition - SQL Injection
SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Soritong MP3 Player 1.0 - Local Buffer Overflow (SEH)
Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow (PoC)
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.asx' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hexamail Server 3.0.0.001 - 'pop3' Remote Overflow (PoC)
Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of servi
28RIESGO
abrir ↗Referência✓ VexDay Proof
sPHPell 1.01 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component 5.3 - 'FtpDownloadFile()' Remote Buffer Overflow
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Compone
28RIESGO
abrir ↗Referência✓ VexDay Proof
BS.Player 2.34 - '.bsl' Universal Overwrite (SEH)
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RIESGO
abrir ↗Referência✓ VexDay Proof
KingSoft - 'UpdateOcx2.dll SetUninstallName()' Heap Overflow (PoC)
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Onli
28RIESGO
abrir ↗Referência✓ VexDay Proof
DGNews 3.0 Beta - 'id' SQL Injection
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
bSpeak 1.10 - 'forumid' Blind SQL Injection
SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
ST-Gallery 0.1a - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1
23RIESGO
abrir ↗Referência✓ VexDay Proof
my-gesuad 0.9.14 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
my-gesuad 0.9.14 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ArtForms 2.1 b7 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7 for Joomla
23RIESGO
abrir ↗Referência✓ VexDay Proof
ArcaVir 2009 < 9.4.320X.9 - 'ps_drv.sys' Local Privilege Escalation
The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.