Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.643exploits catalogados
38.069CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.380GitHub PoC 15.693VulnCheck XDB 9136Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bradabra 2.0.5 - '/include/includes.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-shop 0.70 - Remote File Deletion
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft PicturePusher - ActiveX Cross-Site Arbitrary File Upload
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Editio
28RIESGO
abrir ↗Referência✓ VexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin wordTube 1.43 - 'wpPATH' Remote File Inclusion
PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, wh
35RIESGO
abrir ↗Referência✓ VexDay Proof
Expert Advisior - 'index.php?id' SQL Injection
SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
PicoFlat CMS 0.5.9 (Windows) - Local File Inclusion
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when r
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress,
35RIESGO
abrir ↗Referência✓ VexDay Proof
PStruh-CZ 1.3/1.5 - 'download.asp' File Disclosure
Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZWebAlbum - Remote File Disclosure
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
GC Auction Platinum - 'cate_id' SQL Injection
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ads Pro - 'dhtml.pl' Remote Command Execution
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par
23RIESGO
abrir ↗Referência✓ VexDay Proof
WFTPD Pro Server 3.23.1.1 - 'APPE' Remote Buffer Overflow (PoC)
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitr
28RIESGO
abrir ↗Referência✓ VexDay Proof
Built2Go PHP Realestate 1.5 - 'event_detail.php' SQL Injection
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Winamp 5.34 - '.mp4' Code Execution
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component mosDirectory 2.3.2 - 'catid' SQL Injection
SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component eWriting 1.2.1 - 'cat' SQL Injection
SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RIESGO
abrir ↗Referência✓ VexDay Proof
SCO UnixWare Merge - 'mcd' Local Privilege Escalation
Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPX 3.5.16 - Cookie Poisoning / Authentication Bypass
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
MailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer Overflow
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mms Gallery PHP 1.0 - 'id' Remote File Disclosure
Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JContentSubscription 1.5.8 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! all
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.