Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9182Nuclei 4447Metasploit 3510✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
TinXCMS 1.1 - Local File Inclusion / Cross-Site Scripting
Multiple directory traversal vulnerabilities in TinX/cms 1.1, when register_globals is enabled, allow remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ikon ADManager 2.1 - Remote Database Disclosure
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
polypager 1.0rc2 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
DomPHP 0.81 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
User Engine Lite ASP - 'users.mdb' Database Disclosure
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPPortal 4.0.0 - 'default1.asp' SQL Injection
SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RIESGO
abrir ↗Referência✓ VexDay Proof
Anata CMS 1.0b5 - 'change.php' Arbitrary Add Admin
change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RIESGO
abrir ↗Referência✓ VexDay Proof
vcart 3.3.2 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Limbo CMS 1.0.4.2 - 'catid' SQL Injection
SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Icewarp Merak Mail Server 9.4.1 - 'Base64FileEncode()' Buffer Overflow (PoC)
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1
23RIESGO
abrir ↗Referência✓ VexDay Proof
SazCart 1.5.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in SazCart 1.5.1, when register_globals is enabled, allow remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
pafileDB 2.0.1 - 'mxBB'/'phpBB' Remote File Inclusion
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as us
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alstrasoft e-Friends 4.21 - Admin Session Retrieve
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free Hosting Manager 1.2/2.0 - Insecure Cookie Handling
Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RIESGO
abrir ↗Referência✓ VexDay Proof
Interact 2.4.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when regis
23RIESGO
abrir ↗Referência✓ VexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quote
23RIESGO
abrir ↗Referência✓ VexDay Proof
cmsWorks 2.2 RC4 - 'mod_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is en
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple QuickTime 7.2/7.3 (OSX/Windows) - RSTP Response Universal
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RIESGO
abrir ↗Referência✓ VexDay Proof
nabopoll 1.2 - Remote Unprotected Admin Section
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a di
23RIESGO
abrir ↗Referência✓ VexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
Multiple cross-site request forgery (CSRF) vulnerabilities in Collabtive 0.4.8 allow remote attackers to hijack the auth
23RIESGO
abrir ↗Referência✓ VexDay Proof
Podcast Generator 1.1 - Remote Code Execution
Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated admini
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.