Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Gforge 4.6 rc1 - 'skill_edit' SQL Injection
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discuz! 6.0.1 - 'searchid' SQL Injection
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
LoCal Calendar 1.1 - 'lcUser.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xfire 1.6.4 - Remote Denial of Service
Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB PlusXL 2.0_272 - 'constants.php' Remote File Inclusion
PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module
23RIESGO
abrir ↗Referência✓ VexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe Photoshop CS2 / CS3 - '.bmp' Local Buffer Overflow
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attac
35RIESGO
abrir ↗Referência✓ VexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adult Banner Exchange Website - 'targetid' SQL Injection
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiteNews 0.1 - 'id' SQL Injection
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
6rbScript 3.3 - 'singerid' SQL Injection
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
6rbScript 3.3 - 'section.php' Local File Inclusion
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' Blind SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RIESGO
abrir ↗Referência✓ VexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
28RIESGO
abrir ↗Referência✓ VexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (3)
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗Referência✓ VexDay Proof
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Referência✓ VexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
QMail Mailing List Manager 1.2 - Database Disclosure
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scripts24 iPost 1.0.1 - 'id' SQL Injection
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.