Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_noticias 1.0 - SQL Injection
SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-Blog 2.0 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RIESGO
abrir ↗Referência✓ VexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RIESGO
abrir ↗Referência✓ VexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin st_newsletter - SQL Injection
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bytehoard 2.1 - 'server.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attac
28RIESGO
abrir ↗Referência✓ VexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to exe
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component NeoReferences 1.3.1 - 'catid' SQL Injection
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla!
23RIESGO
abrir ↗Referência✓ VexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RIESGO
abrir ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Serv-U FTP Server 7.3 - (Authenticated) Remote FTP File Replacement
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote auth
28RIESGO
abrir ↗Referência✓ VexDay Proof
Visual Events Calendar 1.1 - 'cfg_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oreon 1.4 / Centreon 1.4.1 - Multiple Remote File Inclusion Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute a
28RIESGO
abrir ↗Referência✓ VexDay Proof
PowerNews 2.5.6 - Local File Inclusion
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_gallery - SQL Injection
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! / Mambo Component SWmenu 4.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Ma
28RIESGO
abrir ↗Referência✓ VexDay Proof
Fastpublish CMS 1.9999 - config[fsBase] Remote File Inclusion
PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attacke
28RIESGO
abrir ↗Referência✓ VexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RIESGO
abrir ↗Referência✓ VexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RIESGO
abrir ↗Referência✓ VexDay Proof
Mozilla Firefox XSL - Parsing Remote Memory Corruption (PoC) (1)
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows r
28RIESGO
abrir ↗Referência✓ VexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RIESGO
abrir ↗Referência✓ VexDay Proof
Sun jre1.6.0_X - isInstalled.dnsResolve Function Overflow
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attack
28RIESGO
abrir ↗Referência✓ VexDay Proof
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RIESGO
abrir ↗Referência✓ VexDay Proof
sflog! 0.96 - Remote File Disclosure
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.