Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir ↗Referência✓ VexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Wp-FileManager 1.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Titan FTP Server 6.03 - 'USER/PASS' Remote Heap Overflow (PoC)
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RIESGO
abrir ↗Referência✓ VexDay Proof
WebMatic 2.6 - 'index_album.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alibaba Alipay - Remove ActiveX Remote Code Execution
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScri
23RIESGO
abrir ↗Referência✓ VexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.x - '/user.php' Security Code Bypass / Arbitrary Add Administrator
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Creamotion - 'securite.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
Blogator-script 0.95 - 'incl_page' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component DBQuery 1.4.1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_
23RIESGO
abrir ↗Referência✓ VexDay Proof
philboard 1.14 - 'philboard_forum.asp' SQL Injection
SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2
60RIESGO
abrir ↗Referência✓ VexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RIESGO
abrir ↗Referência✓ VexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe Album Starter 3.2 - Unchecked Local Buffer Overflow
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remot
28RIESGO
abrir ↗Referência✓ VexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RIESGO
abrir ↗Referência✓ VexDay Proof
ChartDirector 4.1 - 'viewsource.php' File Disclosure
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive file
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZebraFeeds 1.0 - 'zf_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RIESGO
abrir ↗Referência✓ VexDay Proof
VMware 'IntraProcessLogging.dll' 5.5.3.42958 - Arbitrary Data Write
Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple HTTPd 1.41 - '/aux' Remote Denial of Service
Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request th
23RIESGO
abrir ↗Referência✓ VexDay Proof
My Gaming Ladder 7.5 - 'ladderid' SQL Injection
SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.01.02 - 'showonly' Blind SQL Injection
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPReferral 5.3 - 'AccountID' Blind SQL Injection
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.