Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
J-OWAMP Web Interface 2.1b - 'link' Remote File Inclusion
PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with i
23RIESGO
abrir ↗Referência✓ VexDay Proof
D-Link DWL-2000AP 2.11 - ARP Flood Remote Denial of Service
D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of
23RIESGO
abrir ↗Referência✓ VexDay Proof
PageSquid CMS 0.3 Beta - 'index.php' SQL Injection
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute FAQ Manager 6.0 - Insecure Cookie Handling
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative acc
23RIESGO
abrir ↗Referência✓ VexDay Proof
Check Point Firewall-1 - PKI Web Service HTTP Header Remote Overflow
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI
23RIESGO
abrir ↗Referência✓ VexDay Proof
Teraway LinkTracker 1.0 - Insecure Cookie Handling
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&l
23RIESGO
abrir ↗Referência✓ VexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.x - 'hfs-fcntl' Kernel Privilege Escalation
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space
23RIESGO
abrir ↗Referência✓ VexDay Proof
E-topbiz Online Store 1 - 'cat_id' SQL Injection
SQL injection vulnerability in index.php in E-topbiz Online Store 1.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPSiteWare RealtyListing 1.0/2.0 - SQL Injection
Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Belkin F5D9230-4 Wireless G Plus MIMO Router - Authentication Bypass
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component 'com_colophon' 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and
23RIESGO
abrir ↗Referência✓ VexDay Proof
BulletProof FTP Client - '.bps' Local Stack Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gobbl CMS 1.0 - Insecure Cookie Handling
admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setti
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPPortal 3.2.5 - Database Disclosure
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alstrasoft Web Email Script Enterprise - 'id' SQL Injection
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
SH-News 3.0 - Insecure Cookie Handling
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniHTTPServer Web Forum & File Sharing Server 4.0 - Add User
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accou
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScarNews 1.2.1 - 'sn_admin_dir' Local File Inclusion
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Form Processor 4.0 - Insecure Cookie Handling
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
My Little Forum 1.7 - 'user.php?id' SQL Injection
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_bayesiannaivefilter 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaiv
23RIESGO
abrir ↗Referência✓ VexDay Proof
DreamLog 0.5 - 'upload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a
23RIESGO
abrir ↗Referência✓ VexDay Proof
LinPHA 1.3.1 - 'new_images.php' Blind SQL Injection
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RIESGO
abrir ↗Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile p
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.