Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência✓ VexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RIESGO
abrir ↗Referência
CVE-2015-6305
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RIESGO
abrir ↗Referência
CVE-2015-6305
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RIESGO
abrir ↗Referência
CVE-2015-6519
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RIESGO
abrir ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RIESGO
abrir ↗Referência✓ VexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência
CVE-2017-15964
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RIESGO
abrir ↗Referência
CVE-2017-15964
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RIESGO
abrir ↗Referência
CVE-2017-15966
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parame
23RIESGO
abrir ↗Referência✓ VexDay Proof
RealPlayer 10.5 - ActiveX Control Denial of Service
A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of s
23RIESGO
abrir ↗Referência
CVE-2017-15966
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parame
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyManga 0.8.1 - 'template.php' Multiple File Inclusions
Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attacker
23RIESGO
abrir ↗Referência
CVE-2017-15967
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pagetool CMS 1.07 - 'pt_upload.php' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execut
23RIESGO
abrir ↗Referência
CVE-2017-15967
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jinzora 2.7 - 'INCLUDE_PATH' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Jinzora Media Jukebox 2.7 and earlier, when register_globals is en
23RIESGO
abrir ↗Referência✓ VexDay Proof
Irokez Blog 0.7.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ciberia Content Federator 1.0.1 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Cont
23RIESGO
abrir ↗Referência
CVE-2017-15968
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication
23RIESGO
abrir ↗Referência
CVE-2017-15969
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata
23RIESGO
abrir ↗Referência✓ VexDay Proof
Calendar MX BASIC 1.0.2 - 'ID' SQL Injection
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência
CVE-2017-15969
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.