Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Maran PHP Shop - 'prod.php' SQL Injection
SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebCards 1.3 - SQL Injection
SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sepal SPBOARD 4.5 - 'board.cgi' Remote Command Execution
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to i
23RIESGO
abrir ↗Referência✓ VexDay Proof
Lama Software 14.12.2007 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir ↗Referência✓ VexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Faethon 2.0 - 'mainpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and ma
23RIESGO
abrir ↗Referência✓ VexDay Proof
IrfanView 3.99 - '.ani' Local Buffer Overflow (1)
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI)
23RIESGO
abrir ↗Referência✓ VexDay Proof
WFTPD Pro Server 3.25 - Site ADMN Remote Denial of Service
Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service
23RIESGO
abrir ↗Referência✓ VexDay Proof
txtshop 1.0b (Windows) - 'Language' Local File Inclusion
Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.1 - 'hash_update_file()' Freed Resource Usage
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupt
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-CON 1.3 - 'include.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cerulean Portal System 0.7b - Remote File Inclusion
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a dire
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyRing 4.1.3b - 'fichier' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Citrix Presentation Server Client - 'WFICA.OCX' ActiveX Heap Buffer Overflow
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.23
35RIESGO
abrir ↗Referência✓ VexDay Proof
ProFTPd 1.3.0/1.3.0a - 'mod_ctrls' 'support' Local Buffer Overflow (1)
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1
23RIESGO
abrir ↗Referência✓ VexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For H
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RIESGO
abrir ↗Referência✓ VexDay Proof
Yerba SACphp 6.3 - Multiple Vulnerabilities
Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galle
23RIESGO
abrir ↗Referência✓ VexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPG.Board 0.0.8Beta2 - Insecure Cookie Handling
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep
23RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module Profile CP 0.91c - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module
23RIESGO
abrir ↗Referência✓ VexDay Proof
CcMail 1.0.1 - 'functions_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHProjekt 5.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeCMS.us 0.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Rae Media Contact MS - Authentication Bypass
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterpri
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.