Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RIESGO
abrir ↗Referência✓ VexDay Proof
News Rover 12.1 Rev 1 - Stack Overflow (1)
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Epistemon 1.0 - 'common.php?inc_path' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
TeamCal Pro 2.8.001 - 'app_root' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP NEWS 3.0 - 'news_detail.asp' SQL Injection
SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_books - 'book_id' SQL Injection
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RIESGO
abrir ↗Referência✓ VexDay Proof
Xero Portal - 'phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP co
28RIESGO
abrir ↗Referência✓ VexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinOS 4.5.5 - 'gBRootPath' Remote File Inclusion
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Q-Shop 3.5 - 'browse.asp' SQL Injection
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
smeweb 1.4b - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.