Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Toner Cart - 'id' SQL Injection
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZWebAlbum - Insecure Cookie Handling
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by se
23RIESGO
abrir ↗Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Codefixer MailingListPro - Database Disclosure
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech DVD Zone - 'cat_id' SQL Injection
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
IntelliTamper 2.07 - HTTP Header Remote Code Execution
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Jobs Zone - 'news_id' SQL Injection
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech MMORPG Zone - 'game_id' SQL Injection
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Phpjobscheduler 3.0 - 'installed_config_file' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc
23RIESGO
abrir ↗Referência✓ VexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir ↗Referência✓ VexDay Proof
RsGallery2 < 1.11.2 - 'rsgallery.html.php' File Inclusion
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for
23RIESGO
abrir ↗Referência✓ VexDay Proof
pPIM 1.0 - Upload/Change Password
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Faethon 2.2 Ultimate - Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
PixelPost 1.7.1 - 'language_full' Local File Inclusion
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir ↗Referência✓ VexDay Proof
PrecisionID Barcode ActiveX 1.3 - Denial of Service
Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZContents CMS 2.0.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
CentiPaid 1.4.2 - 'centipaid_class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
NULL FTP Server 1.1.0.7 - 'Site' Command Injection
Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Live TV Script - 'index.php?mid' SQL Injection
SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Weblogicnet - 'files_dir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.