Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Original 0.11 - 'config.inc.php?x[1]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.asx' 'HREF' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir ↗Referência✓ VexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current use
23RIESGO
abrir ↗Referência✓ VexDay Proof
Web Calendar 4.1 - Blind SQL Injection
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenEMR 2.8.1 - 'fileroot' Remote File Inclusion
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Rising AntiVirus Online Scanner - Insecure Method Flaw
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner all
28RIESGO
abrir ↗Referência✓ VexDay Proof
events Calendar 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Ca
23RIESGO
abrir ↗Referência✓ VexDay Proof
CGX 20050314 - 'pathCGX' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZeroShell 1.0beta11 - Remote Code Execution
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell meta
60RIESGO
abrir ↗Referência✓ VexDay Proof
IF-CMS 2.0 - 'id' Blind SQL Injection
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlie
28RIESGO
abrir ↗Referência✓ VexDay Proof
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
23RIESGO
abrir ↗Referência✓ VexDay Proof
Audacity 1.2.6 - '.gro' Local Buffer Overflow (PoC)
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacit
28RIESGO
abrir ↗Referência✓ VexDay Proof
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
TAGWORX.CMS 3.00.02 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClickCart 6.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Igloo 0.1.9 - 'Wiki.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
zBlog 1.2 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.