Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
webSPELL 4.2.0c - Bypass BBCode Cross-Site Scripting Cookie Stealing
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HT
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RIESGO
abrir ↗Referência✓ VexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RIESGO
abrir ↗Referência✓ VexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
BoastMachine 3.1 - 'mail.php' id SQL Injection
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
YourFreeScreamer 1.0 - 'serverPath' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
GPB Bulletin Board - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpEmployment - 'PHP Upload' Arbitrary File Upload
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RIESGO
abrir ↗Referência✓ VexDay Proof
Agora 1.4 RC1 - 'MysqlfinderAdmin.php' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_glob
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Explorer - '.AVI' File Denial of Service
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause
28RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Recipe 1.0 - 'path_to_folder' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Carscripts Classifieds - 'cat' SQL Injection
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RIESGO
abrir ↗Referência✓ VexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
MoviePlay 4.76 - '.lst' Local Buffer Overflow
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Login 0.7 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
audioCMS arash 0.1.4 - 'arashlib_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in audioCMS arash 0.1.4 allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência✓ VexDay Proof
Madirish Webmail 2.0 - 'addressbook.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebChat 0.78 - 'login.php?rid' SQL Injection
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RIESGO
abrir ↗Referência✓ VexDay Proof
AgerMenu 0.01 - 'top.inc.php?rootdir' Remote File Inclusion
PHP remote file inclusion vulnerability in examples/inc/top.inc.php in AgerMenu 0.03 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.