Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Scribe 0.2 - PHP Remote Code Execution
Directory traversal vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to create or ove
23RIESGO
abrir ↗Referência✓ VexDay Proof
Creative Software AutoUpdate Engine - ActiveX Stack Overflow
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RIESGO
abrir ↗Referência✓ VexDay Proof
SNMPv3 - HMAC Validation error Remote Authentication Bypass
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-S
35RIESGO
abrir ↗Referência✓ VexDay Proof
Sun Solaris 10 - snoop(1M) Utility Remote Command Execution
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o op
28RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module myAlbum-P 2.0 - 'cid' SQL Injection
SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
GL-SH Deaf Forum 6.4.4 - Local File Inclusion
Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and
23RIESGO
abrir ↗Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
Home FTP Server 1.4.5 - Remote Denial of Service
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode conn
23RIESGO
abrir ↗Referência✓ VexDay Proof
IP Reg 0.4 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
CCleague Pro 1.0.1RC1 - 'cookie' Remote Code Execution
Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Eurologon CMS - 'files.php' Arbitrary File Download
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quick TFTP Server Pro 2.1 - Remote Overflow (SEH)
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RIESGO
abrir ↗Referência✓ VexDay Proof
TFTP Server 1.4 - ST Buffer Overflow
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RIESGO
abrir ↗Referência✓ VexDay Proof
BASE 1.2.4 - melissa Snort Frontend Remote File Inclusion
PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_gl
50RIESGO
abrir ↗Referência✓ VexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute
35RIESGO
abrir ↗Referência✓ VexDay Proof
Neat weblog 0.2 - 'articleId' SQL Injection
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
SlimCMS 1.0.0 - 'redirect.php' Privilege Escalation
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative us
23RIESGO
abrir ↗Referência✓ VexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
DivX Player 6.7 - '.srt' File Subtitle Parsing Buffer Overflow
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RIESGO
abrir ↗Referência✓ VexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
FizzMedia 1.51.2 - SQL Injection
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
FaScript FaPersianHack 1.0 - SQL Injection
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogMe PHP 1.1 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Admin Password Changing
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cplinks 1.03 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScozNews 1.2.1 - 'mainpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Online Rental Property Script 4.5 - 'pid' SQL Injection
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP infoboard 7 plus - Multiple Vulnerabilities
SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to i
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.