Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Cplinks 1.03 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RIESGO
abrir ↗Referência✓ VexDay Proof
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows re
35RIESGO
abrir ↗Referência✓ VexDay Proof
BulletProof FTP Client - '.bps' Local Stack Overflow (PoC)
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alstrasoft Web Email Script Enterprise - 'id' SQL Injection
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_bayesiannaivefilter 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaiv
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service (Metasploit)
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express
35RIESGO
abrir ↗Referência✓ VexDay Proof
BLOG 1.55B - 'image_upload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute a
28RIESGO
abrir ↗Referência✓ VexDay Proof
DFF PHP Framework API - 'Data Feed File' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PGP Desktop 9.0.6 - 'PGPwded.sys' Local Denial of Service
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows l
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hacks List phpBB Mod 1.21 - SQL Injection
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
HotScripts Clone Script - SQL Injection
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod Classifieds - 'lid' SQL Injection
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (1)
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir ↗Referência✓ VexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Dada Mail Manager 2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for
35RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft Ajax Portal 3.0 - Authentication Bypass
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zip Store Chat 4.0/5.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenEMR 2.8.1 - 'srcdir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
Elecard AVC HD player - '.m3u' / '.xpl' Local Stack Overflow (PoC)
Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an
23RIESGO
abrir ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.2.1 - Remote Denial of Service
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long
23RIESGO
abrir ↗Referência✓ VexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ksemail - Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local file
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyPHPsite - Local File Inclusion
Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPEasyData Pro 2.2.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.