Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apache mod_dav / svn - Remote Denial of Service
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav
35RIESGO
abrir ↗Referência✓ VexDay Proof
Seagull 0.6.3 - 'files' Remote File Disclosure
Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Password Protector SD 1.3.1 - Insecure Cookie Handling
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
Comodo AntiVirus 2.0 - 'ExecuteStr()' Remote Command Execution
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteS
35RIESGO
abrir ↗Referência✓ VexDay Proof
Family Connections CMS 1.9 - SQL Injection
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authen
23RIESGO
abrir ↗Referência✓ VexDay Proof
Worldweaver DX Studio Player < 3.0.29.1 Firefox plugin - Command Injection
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RIESGO
abrir ↗Referência✓ VexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MooFAQ (com_moofaq) - Local File Inclusion
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Jooml
38RIESGO
abrir ↗Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to lis
23RIESGO
abrir ↗Referência✓ VexDay Proof
Virtue Shopping Mall - 'cid' SQL Injection
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Virtue Book Store - 'cid' SQL Injection
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component musepoes - 'aid' SQL Injection
SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Virtue Classifieds - 'category' SQL Injection
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPortal 1 - 'topicler.php?id' SQL Injection
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6i - '.tta' File Parsing Heap Overflow (PoC)
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Jumi - 'fileid' Blind SQL Injection
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authen
23RIESGO
abrir ↗Referência✓ VexDay Proof
Lycos FileUploader Control - ActiveX Remote Buffer Overflow
Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUpl
28RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.
23RIESGO
abrir ↗Referência✓ VexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo
28RIESGO
abrir ↗Referência✓ VexDay Proof
Zip Store Chat 4.0/5.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpWebThings 1.5.2 - MD5 Hash Retrieve/File Disclosure
SQL injection vulnerability in fdown.php in phpWebThings 1.5.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
SapLPD 6.28 (Windows x86) - Remote Buffer Overflow
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to
60RIESGO
abrir ↗Referência✓ VexDay Proof
adaptweb 0.9.2 - Local File Inclusion / SQL Injection
SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in news/index.php in Campus Virtual-LMS allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.