Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RIESGO
abrir ↗Referência✓ VexDay Proof
RS-CMS 2.1 - 'key' SQL Injection
SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.01.02 - 'gallery.php' Blind SQL Injection
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência✓ VexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foro Domus 2.10 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RIESGO
abrir ↗Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Referência✓ VexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated user
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'crack_opendict()' Local Buffer Overflow
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Macromedia 10.1.4.20 - 'SwDir.dll' Internet Explorer Stack Overflow Denial of Service
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote
28RIESGO
abrir ↗Referência✓ VexDay Proof
ProSysInfo TFTP Server TFTPDWIN 0.4.2 - 'UDP' Denial of Service
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP p
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'cpdf_open()' Local Source Code Disclosure
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensiti
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.6 - 'snmpget()' Object id Local Buffer Overflow
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.3 - 'snmpget()' Object id Local Buffer Overflow
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗Referência✓ VexDay Proof
SonicMailer Pro 3.2.3 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component AlphaUserPoints - SQL Injection
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) compo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Softerra Time-Assistant 6.2 - 'inc_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attacke
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.