Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗Referência✓ VexDay Proof
DD-WRT HTTPd Daemon/Service - Remote Command Execution
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijac
23RIESGO
abrir ↗Referência✓ VexDay Proof
iBoutique 4.0 - 'cat' SQL Injection
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
CFMBLOG - 'categorynbr' Blind SQL Injection
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Euphonics Audio Player 1.0 - '.pls' Universal Local Buffer Overflow
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RIESGO
abrir ↗Referência✓ VexDay Proof
AvailScript Jobs Portal Script - 'jid' SQL Injection
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
SailPlanner 0.3a - Authentication Bypass
Multiple SQL injection vulnerabilities in SailPlanner 0.3a allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Maxum Rumpus 6.0 - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation f
23RIESGO
abrir ↗Referência✓ VexDay Proof
w3blabor CMS 3.3.0 - Authentication Bypass
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disa
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Facil-CMS 0.1RC - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗Referência✓ VexDay Proof
smNews 1.0 - Authentication Bypass / Column Truncation
SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
RM Downloader 3.0.0.9 - '.RAM' Local Buffer Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗Referência✓ VexDay Proof
vxFtpSrv 2.0.3 - 'CWD' Remote Buffer Overflow (PoC)
Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência✓ VexDay Proof
CHILKAT ASP String - 'CkString.dll 1.1 SaveToFile()' Insecure Method
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Visa Zone - 'news_id' SQL Injection
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code
28RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Amaya 11.1 - W3C Editor/Browser 'defer' Remote Stack Overflow
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script
28RIESGO
abrir ↗Referência✓ VexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod recept - 'kat_id' SQL Injection
SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component prayercenter 1.4.9 - 'id' SQL Injection
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RIESGO
abrir ↗Referência✓ VexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.