Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência✓ VexDay Proof
IBiz E-Banking Integrator 2.0 - ActiveX Edition Insecure Method
The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator)
23RIESGO
abrir ↗Referência
CVE-2017-6529
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID pa
23RIESGO
abrir ↗Referência
CVE-2010-1934
Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, al
23RIESGO
abrir ↗Referência
CVE-2010-1934
Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, al
23RIESGO
abrir ↗Referência
CVE-2018-10118
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir ↗Referência✓ VexDay Proof
Entertainment CMS - Local File Inclusion / Remote Command Execution
Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include an
23RIESGO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'rename' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir ↗Referência✓ VexDay Proof
Social Site Generator 2.0 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
2532/Gigs 1.2.1 - 'activateuser.php' Local File Inclusion
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute
23RIESGO
abrir ↗Referência
CVE-2015-2838
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote
23RIESGO
abrir ↗Referência
CVE-2010-1935
Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, al
23RIESGO
abrir ↗Referência
CVE-2024-0399
WooCommerce Customers Manager < 29.7 - Subscriber+ SQL Injection
41RIESGO
abrir ↗Referência
CVE-2016-4486
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module htmltonuke 2.0alpha - 'htmltonuke.php' Remote File Inclusion
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, modu
23RIESGO
abrir ↗Referência
CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir ↗Referência
CVE-2018-15918
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission
23RIESGO
abrir ↗Referência✓ VexDay Proof
TlAds 1.0 - Remote Insecure Cookie Handling
tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login coo
23RIESGO
abrir ↗Referência✓ VexDay Proof
PortailPHP mod_phpalbum 2.1.5 - 'chemin' Remote File Inclusion
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuoteBook - Remote Configuration File Disclosure
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bloginator 1a - Cookie Bypass / SQL Injection
Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYou
23RIESGO
abrir ↗Referência✓ VexDay Proof
sBLOG 0.7.3 Beta - '/inc/lang.php' Local File Inclusion
Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Jobs 2.4 - 'cid' SQL Injection
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 al
23RIESGO
abrir ↗Referência✓ VexDay Proof
DevMass Shopping Cart 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Anon Proxy Server 0.1000 - Remote Command Execution
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Referência
CVE-2018-0745
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.