Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
PHP TV Portal 2.0 - 'mid' SQL Injection
SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes
23RIESGO
abrir ↗Referência✓ VexDay Proof
VImpX ActiveX (VImpX.ocx 4.7.3.0) - Remote Buffer Overflow
Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mole Group Airline Ticket Script - SQL Injection
SQL injection vulnerability in info.php in Mole Group Airline Ticket Sale Script allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZ-Ticket 0.0.1 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
wotw 5.0 - Local/Remote File Inclusion
Directory traversal vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xfire 1.6.4 - Remote Denial of Service
Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPBasket - 'pro_id' SQL Injection
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB PlusXL 2.0_272 - 'constants.php' Remote File Inclusion
PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência✓ VexDay Proof
Arcadem LE 2.04 - 'loadadminpage' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RIESGO
abrir ↗Referência✓ VexDay Proof
TEC-IT TBarCode - OCX ActiveX Arbitrary File Overwrite
The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files
23RIESGO
abrir ↗Referência✓ VexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adult Banner Exchange Website - 'targetid' SQL Injection
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Censura 1.15.04 - 'censura.php?vendorid' SQL Injection
SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiteNews 0.1 - 'id' SQL Injection
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
AdminBot 9.0.5 - 'live_status.lib.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execu
35RIESGO
abrir ↗Referência✓ VexDay Proof
Diesel Pay Script - 'area' SQL Injection
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
83RIESGO
abrir ↗Referência✓ VexDay Proof
e107 Plugin Image Gallery 0.9.6.2 - SQL Injection
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpCC 4.2 Beta - 'base_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
TYPSoft FTP Server 1.11 - 'ABORT' Remote Denial of Service
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort
23RIESGO
abrir ↗Referência✓ VexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean FTP Server 1.00 - Denial of Service
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.