Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.523GitHub PoC 14.289VulnCheck XDB 8710Nuclei 4319Metasploit 3476✓ solo verificadosrecientespopularesriesgo
22.523 exploits
Referência✓ VexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RIESGO
abrir ↗Referência✓ VexDay Proof
CKGold Shopping Cart 2.0 - 'category.php' Blind SQL Injection
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
AnyInventory 2.0 - 'Environment.php' Remote File Inclusion
PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabl
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMytourney - 'menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP cod
35RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Basic 6.0 - VBP_Open OLE Local CodeExec
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Basic Enterprise 6.0 SP6 - Code Execution
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual FoxPro 6.0 - FPOLE.OCX 6.0.8450.0 Remote (PoC)
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the
35RIESGO
abrir ↗Referência✓ VexDay Proof
GlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap Overflow
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
GlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap Overflow
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
AtomixMP3 2.3 - '.pls' Local Buffer Overflow
Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.0 - Local File Inclusion
Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to inclu
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebED 0.8999a - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers
35RIESGO
abrir ↗Referência✓ VexDay Proof
phpRealty 0.02 - 'MGR' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP cod
35RIESGO
abrir ↗Referência✓ VexDay Proof
RW::Download 2.0.3 lite - 'index.php?dlid' SQL Injection
Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio 6.0 - 'VBTOVSI.dll 1.0.0.0' File Overwrite
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1
28RIESGO
abrir ↗Referência✓ VexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0 SaveToFile()' Insecure Method
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Co
23RIESGO
abrir ↗Referência
CVE-2017-7293
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RIESGO
abrir ↗Referência
CVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir ↗Referência
CVE-2017-7358
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar
23RIESGO
abrir ↗Referência
CVE-2023-31748
Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the exe
41RIESGO
abrir ↗Referência
CVE-2017-7411
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RIESGO
abrir ↗Referência
CVE-2017-7411
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RIESGO
abrir ↗Referência
CVE-2023-31874
Yank Note (YN) 3.52.1 allows execution of arbitrary code when a crafted file is opened, e.g., via nodeRequire('child_pro
41RIESGO
abrir ↗Referência
CVE-2017-8671
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RIESGO
abrir ↗Referência
CVE-2017-8687
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir ↗Referência
CVE-2017-8751
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user
35RIESGO
abrir ↗Referência
CVE-2017-8824
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privilege
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component wmtportfolio 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtpor
23RIESGO
abrir ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.07 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiveAlbum 0.9.0 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remot
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.