Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8693Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.429 exploits
Referência✓ VexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RIESGO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RIESGO
abrir ↗Referência
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir ↗Referência
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Referência
CVE-2020-17506
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RIESGO
abrir ↗Referência
CVE-2023-27524
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗Referência✓ VexDay Proof
Rae Media Contact MS - Authentication Bypass
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterpri
23RIESGO
abrir ↗Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir ↗Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir ↗Referência
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RIESGO
abrir ↗Referência
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir ↗Referência
CVE-2008-6392
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência
CVE-2018-14933
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RIESGO
abrir ↗Referência
CyberArk Viewfinity 5.5.10.95 - Local Privilege Escalation
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user v
41RIESGO
abrir ↗Referência
CVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir ↗Referência
CVE-2017-1129
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir ↗Referência✓ VexDay Proof
EasyMail - ActiveX 'emmailstore.dll 6.5.0.3' Remote Buffer Overflow
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2020-1350
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir ↗Referência✓ VexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
TSplus 16.0.2.14 - Remote Access Insecure Files and Folders Permissions
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Diesel Pay Script - 'area' SQL Injection
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
TSplus 16.0.0.0 - Remote Work Insecure Files and Folders
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
23RIESGO
abrir ↗Referência✓ VexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hunkaray Duyuru Scripti - 'tr' SQL Injection
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.