Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9182Nuclei 4447Metasploit 3510✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
AuraCMS Forum Module - SQL Injection
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
DreamPics Builder - 'page' SQL Injection
SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
PhShoutBox 1.5 - Insecure Cookie Handling
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain p
23RIESGO
abrir ↗Referência✓ VexDay Proof
mail2forum phpBB Mod 1.2 - 'm2f_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oracle 10g - 'LT.FINDRICSET' SQL Injection (IDS Evasion)
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Webring Website Script - 'category.php?cat' SQL Injection
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component 5.1 - HttpDownloadFile() Insecure Method
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer
23RIESGO
abrir ↗Referência✓ VexDay Proof
Norton Ghost Support module for EasySetup wizard - Remote Denial of Service (PoC)
Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in
23RIESGO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
XPOZE Pro 3.06 - 'uid' SQL Injection
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.3 - PHP_ntuser ntuser_getuserlist() Local Buffer Overflow (PoC)
Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial
23RIESGO
abrir ↗Referência✓ VexDay Proof
WBB2-Addon: Acrotxt 1.0 - 'show' SQL Injection
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual FoxPro 6.0 - FPOLE.OCX 6.0.8450.0 Remote (PoC)
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the
35RIESGO
abrir ↗Referência✓ VexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Icewarp Merak Mail Server 9.4.1 - 'Base64FileEncode()' Buffer Overflow (PoC)
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1
23RIESGO
abrir ↗Referência✓ VexDay Proof
jetAudio 7.x - '.m3u' Local Overwrite (SEH)
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Txx CMS 0.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code v
35RIESGO
abrir ↗Referência✓ VexDay Proof
eLitius 1.0 - 'banner-details.php?id' SQL Injection
SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Txx CMS 0.2 - Multiple Remote File Inclusions
Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.