Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
OraMon 2.0.1 - Remote Configuration File Disclosure
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dayfox Blog 4 - 'postpost.php' Remote Code Execution
Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute
35RIESGO
abrir ↗Referência✓ VexDay Proof
E RESERV 2.1 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
EkinBoard 1.1.0 - Arbitrary File Upload / Authentication Bypass
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pinnacle Studio 12 - '.hfz' Directory Traversal
Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Syst
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
DBImageGallery 1.2.2 - 'donsimg_base_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DBImageGallery 1.2.2 allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component jabode - 'id' SQL Injection
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (1)
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
MagicISO 5.4 (build239) - '.cue' Heap Overflow (PoC)
Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
ModuleBuilder 1.0 - 'file' Remote File Disclosure
Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - Local/Remote File Inclusion
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inje
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component nfnaddressbook 0.4 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Half-Life CSTRIKE Server 1.6 - 'no-steam' Denial of Service
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple cr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Moodle 1.5.2 - 'moodledata' Remote Session Disclosure
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides
23RIESGO
abrir ↗Referência✓ VexDay Proof
ActualAnalyzer Lite (free) 2.78 - Local File Inclusion
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to incl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (2)
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Community Builder 1.0.1 - Blind SQL Injection
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 an
23RIESGO
abrir ↗Referência✓ VexDay Proof
mailwatch 1.0.4 - 'doc' Local File Inclusion
Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6/5.2.1 - ext/gd Already Freed Resources Usage
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RIESGO
abrir ↗Referência✓ VexDay Proof
PNPHPBB2 < 1.2 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Live Helper 2.0 - 'abs_path' Remote File Inclusion
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.