Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Downline Goldmine newdownlinebuilder - SQL Injection
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenDock Easy Blog 1.4 - 'doc_directory' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Hosting Index - 'id' SQL Injection
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Thecus N5200Pro NAS Server Control Panel - Remote File Inclusion
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Visit Counter 0.4 - 'datespan' SQL Injection
SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Real Estate Listings - 'search.php' SQL Injection
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
iScripts EasyIndex - 'produid' SQL Injection
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
CustomCMS 4.0 - 'print.php' SQL Injection
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
CYASK 3.x - 'neturl' Local File Disclosure
Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Linux Kernel < 2.6.26.4 - SCTP Kernel Memory Disclosure
The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implemen
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Quiz 0.81 - 'tid' SQL Injection
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ownbiblio 1.5.3 - 'catid' SQL Injection
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RIESGO
abrir ↗Referência✓ VexDay Proof
Yourownbux 3.1/3.2 Beta - SQL Injection
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
myPHPNuke < 1.8.8_8rc2 - 'artid' SQL Injection
SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
KISGB (tmp_theme) 5.1.1 - Local File Inclusion
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Reciprocal Links Manager 1.1 - 'site' SQL Injection
SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpEventMan 1.0.2 - 'level' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
EasyClassifields 3.0 - 'go' SQL Injection
SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Brim 2.0.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenti
23RIESGO
abrir ↗Referência✓ VexDay Proof
phsBlog 0.2 - Bypass SQL Injection Filtering
Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Friendly Technologies - Read/Write Registry/Read Files
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ultra Office - ActiveX Control Arbitrary File Corruption
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Contr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Creator CMS 5.0 - 'sideid' SQL Injection
Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
z-breaknews 2.0 - 'single.php' SQL Injection
SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.