Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Service Provider Management System v1.0 - SQL Injection
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated us
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
WengoPhone 2.x - SIP Phone Remote Denial of Service
WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co
23RIESGO
abrir ↗Referência✓ VexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RIESGO
abrir ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - Remote Command Execution
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP TopTree BBS 2.0.1a - 'right_file' Remote File Inclusion
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
pNews 2.08 - 'shownews' SQL Injection
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
HRS Multi - 'key' Blind SQL Injection
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
DL PayCart 1.34 - Admin Password Changing
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
VS-News-System 1.2.1 - 'newsordner' Remote File Inclusion
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPmyGallery 1.0beta2 - Local/Remote File Inclusion
Directory traversal vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
TWiki 4.2.0 - 'configure' Remote File Disclosure
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RIESGO
abrir ↗Referência✓ VexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Toner Cart - 'id' SQL Injection
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals
23RIESGO
abrir ↗Referência✓ VexDay Proof
DeluxeBB 1.07 - Remote Create Admin
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Survey Poll - 'catid' SQL Injection
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Top 100 1.2 - Arbitrary Delete Stats
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary user
23RIESGO
abrir ↗Referência✓ VexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Restaurante - Arbitrary File Upload
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attacker
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.