Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Thyme Calendar 1.3 - SQL Injection
SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ottoman CMS 1.1.3 - '?default_path=' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpCommunityCalendar 4.0.3 - Cross-Site Scripting / SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RIESGO
abrir ↗Referência✓ VexDay Proof
Family Connections CMS 1.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated user
23RIESGO
abrir ↗Referência✓ VexDay Proof
BigACE 2.4 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Tuned Studios Templates - Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message r
28RIESGO
abrir ↗Referência✓ VexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acoustica Mixcraft 4.2 Build 98 - 'mx4' Local Buffer Overflow
Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pc4Uploader 9.0 - Blind SQL Injection
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPNS 1.1 - 'shownews.php?id' SQL Injection
SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Anserv Auction XL - 'cat' SQL Injection
SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
GForge 4.5.19 - Multiple SQL Injections
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Belkin F5D9230-4 Wireless G Plus MIMO Router - Authentication Bypass
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component 'com_catalogshop' 1.0b1 - SQL Injection
SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! al
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup/Make Directory
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cahier de texte 2.0 - 'lire.php' SQL Injection
Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.