Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência
CVE-2015-3141
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Limbo CMS 1.0.4.2 - 'catid' SQL Injection
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute a
23RIESGO
abrir ↗Referência
CVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17606
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17606
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17608
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17608
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir ↗Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RIESGO
abrir ↗Referência
CVE-2017-17610
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid paramet
23RIESGO
abrir ↗Referência
CVE-2006-2315
PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHP::HTML 0.6.4 - 'PHPhtml.php' Remote File Inclusion
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute
35RIESGO
abrir ↗Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência
CVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RIESGO
abrir ↗Referência✓ VexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RIESGO
abrir ↗Referência
CVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RIESGO
abrir ↗Referência
CVE-2017-17620
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RIESGO
abrir ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.