Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RIESGO
abrir ↗Referência✓ VexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RIESGO
abrir ↗Referência✓ VexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RIESGO
abrir ↗Referência✓ VexDay Proof
RS-CMS 2.1 - 'key' SQL Injection
SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.01.02 - 'gallery.php' Blind SQL Injection
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foro Domus 2.10 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RIESGO
abrir ↗Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Referência✓ VexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated user
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'crack_opendict()' Local Buffer Overflow
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Macromedia 10.1.4.20 - 'SwDir.dll' Internet Explorer Stack Overflow Denial of Service
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote
28RIESGO
abrir ↗Referência✓ VexDay Proof
ProSysInfo TFTP Server TFTPDWIN 0.4.2 - 'UDP' Denial of Service
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP p
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'cpdf_open()' Local Source Code Disclosure
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensiti
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'snmpget()' Object id Local Buffer Overflow
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.3 - 'snmpget()' Object id Local Buffer Overflow
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.