Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.506Exploit-DB 24.485GitHub PoC 15.787VulnCheck XDB 9186Nuclei 4448Metasploit 3512✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Myspace Clone Script - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component SMF Forum 1.3.1.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and M
23RIESGO
abrir ↗Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RIESGO
abrir ↗Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic pa
23RIESGO
abrir ↗Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RIESGO
abrir ↗Referência✓ VexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
IceBB 1.0-rc5 - Remote Create Admin
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
ezusermanager 1.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RIESGO
abrir ↗Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Referência✓ VexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RIESGO
abrir ↗Referência✓ VexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RIESGO
abrir ↗Referência✓ VexDay Proof
C-Arbre 0.6PR7 - 'ROOT_PATH' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbit
28RIESGO
abrir ↗Referência✓ VexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP1 - Arbitrary File Upload
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RIESGO
abrir ↗Referência✓ VexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPThai.Net Forum 8.5 - Remote Database Disclosure
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.