Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0.5 - 'day' SQL Injection
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RIESGO
abrir ↗Referência✓ VexDay Proof
Youtuber Clone - SQL Injection
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
CoolPlayer 2.18 - '.m3u' File Local Buffer Overflow
Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpLinkat 0.1 - Insecure Cookie Handling / SQL Injection
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.2.8 - 'id_document' Blind SQL Injection
SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpLinkat 0.1 - Insecure Cookie Handling / SQL Injection
SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
HIOX Browser Statistics 2.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Joomtracker 1.01 - SQL Injection
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acc Statistics 1.1 - Insecure Cookie Handling
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir ↗Referência✓ VexDay Proof
eLitius 1.0 - Remote Command Execution
Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intende
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chilkat Socket ActiveX 2.3.1.1 - Arbitrary File Creation
Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scout Portal Toolkit 1.4.0 - 'forumid' SQL Injection
SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Lance 1.52 - 'catid' SQL Injection
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
DZCP (deV!L_z Clanportal) 1.34 - 'id' SQL Injection
SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP 1.3.4 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Trend Micro Internet Security Pro 2009 - Priviliege Escalation
The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Securit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netgear SSL312 Router - Denial of Service
cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de
23RIESGO
abrir ↗Referência✓ VexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RIESGO
abrir ↗Referência✓ VexDay Proof
FipsCMS 2.1 - 'print.asp' SQL Injection
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Randshop 1.1.1 - 'header.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
MikroTik RouterOS 3.13 - SNMP write (Set request)
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (N
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free Download Manager 2.5/3.0 - Authorisation Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RIESGO
abrir ↗Referência✓ VexDay Proof
RSSonate - 'xml2rss.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.