Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Advanced Links Management (ALM) 1.52 - SQL Injection
SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Software - 'id' SQL Injection
SQL injection vulnerability in software-description.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 6.0.2900 SP2 - CSS Attribute Denial of Service
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a
38RIESGO
abrir ↗Referência✓ VexDay Proof
MiniPort@l 0.1.5 Beta - 'skiny' Remote File Inclusion
PHP remote file inclusion vulnerability in menu.php in MiniPort@l 2.0 and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
RaidenFTPd 2.4 build 3620 - Remote Denial of Service
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service
23RIESGO
abrir ↗Referência✓ VexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (PoC)
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RIESGO
abrir ↗Referência✓ VexDay Proof
ModSecurity < 2.5.9 - Remote Denial of Service
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a m
28RIESGO
abrir ↗Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Web Slider 0.6 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
StoreFront for Gallery - 'GALLERY_BASEDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Shopping Mall - Insecure Cookie Handling
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adm
23RIESGO
abrir ↗Referência✓ VexDay Proof
SilverSHielD 1.0.2.34 - Denial of Service
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to
23RIESGO
abrir ↗Referência✓ VexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RIESGO
abrir ↗Referência✓ VexDay Proof
SCart 2.0 - 'page' Remote Code Execution
scart.cgi in SCart 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the page parame
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RIESGO
abrir ↗Referência✓ VexDay Proof
miniPortail 2.2 - Cross-Site Scripting / Local File Inclusion
Cross-site scripting (XSS) vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to inject
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Kbase 1.0 - SQL Injection
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sepcity Shopping Mall - SQL Injection
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sepcity Classified - 'ID' SQL Injection
SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RIESGO
abrir ↗Referência✓ VexDay Proof
DeluxeBB 1.2 - Blind SQL Injection
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebBiscuits Modules Controller 1.1 - Remote File Inclusion / Remote File Disclosure
PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Blog:CMS 4.1.3 - 'NP_UserSharing.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPortal 1.1 - 'file_op' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in RPortal 1.1 and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Noname CMS 1.0 - Multiple SQL Injections
SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.