Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8703Nuclei 4314Metasploit 3474✓ solo verificadosrecientespopularesriesgo
24.455 exploits
Exploit-DB✓ VexDay Proof
ACGV News 0.9.1 - 'header.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Uni-vert PHPLeague 0.82 - 'Joueurs.php' SQL Injection
SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SoftBB 0.1 - 'Page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AnnonceV News Script 1.1 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DSocks 1.3 - 'Name' Buffer Overflow (PoC)
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (1)
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Address Book Web Server 1.2 - Remote Format String
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (cr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke MyHeadlines 4.3.1 Module - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Proxima 6.0 - 'BB_Smilies.php' Local File Inclusion
Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote auth
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yappa-ng 2.3.1 - 'admin_modules' Remote File Inclusion
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Annuaire 1Two 2.2 - SQL Injection
SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autentificator 2.01 - 'Aut_Verifica.Inc.php' SQL Injection
SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VBZoom 1.11 - 'profile.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Internet Security Systems 3.6 BlackICE - Local Denial of Service
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a den
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PowerZip 7.06.38950 - 'Filename Handling' Local Buffer Overflow
Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBace Light - 'login_check.php' Remote File
PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 2.0.3 - 'Headeruserdata.php' SQL Injection
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HLstats 1.34 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'search.php?GLOBALS[language_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'showguestbook.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Digiappz Freekot 1.01 - ASP SQL Injection
Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZipCentral 4.01 - '.ZIP' File Handling Local Buffer Overflow
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'shownews.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'showlinks.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IwebNegar 1.1 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents 2.0 - 'gallery_summary.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents 2.0.3 - 'review_summary.php?GLOBALS[admin_home]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.