Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Module MambWeather 1.8.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier compo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enigma 2 Coppermine Bridge - 'boarddir' Remote File Inclusion
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
GNU/Linux mbse-bbs 0.70.0 - Local Buffer Overflow
Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string
23RIESGO
abrir ↗Referência✓ VexDay Proof
IrfanView 4.00 - '.iff' Local Buffer Overflow
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RIESGO
abrir ↗Referência✓ VexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
burnCMS 0.2 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RIESGO
abrir ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String
Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote at
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Portfol 1.2 - 'vcatid' SQL Injection
SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin mygallery 1.4b4 - Remote File Inclusion
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin fo
35RIESGO
abrir ↗Referência✓ VexDay Proof
Demo4 CMS - 'id' SQL Injection
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_loudmouth 4.0j - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and p
23RIESGO
abrir ↗Referência✓ VexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
SnippetMaster Webpage Editor 2.2.2 - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to i
23RIESGO
abrir ↗Referência✓ VexDay Proof
PNPHPBB2 < 1.2i - 'PHPEx' Local File Inclusion
Directory traversal vulnerability in printview.php in PNphpBB2 1.2i and earlier allows remote attackers to include and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMSmelborp Beta - 'user_standard.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashGameScript 1.5.4 - 'index.php?func' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.