Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.506Exploit-DB 24.485GitHub PoC 15.787VulnCheck XDB 9186Nuclei 4448Metasploit 3512✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
IBM Domino Web Access Upload Module - Overwrite (SEH)
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RIESGO
abrir ↗Referência✓ VexDay Proof
phpListPro 2.0.1 - 'Language' Remote Code Execution
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, a
23RIESGO
abrir ↗Referência✓ VexDay Proof
WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
DMXReady Member Directory Manager 1.1 - SQL Injection
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and ea
23RIESGO
abrir ↗Referência✓ VexDay Proof
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newspo
28RIESGO
abrir ↗Referência✓ VexDay Proof
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pragyan CMS 2.6.4 - Multiple SQL Injections
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Igloo 0.1.9 - 'Wiki.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClickCart 6.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in customer_login_check.asp in ClickTech ClickCart 6.0 allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Audacity 1.2.6 - '.gro' Local Buffer Overflow (PoC)
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacit
28RIESGO
abrir ↗Referência✓ VexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
23RIESGO
abrir ↗Referência✓ VexDay Proof
IF-CMS 2.0 - 'id' Blind SQL Injection
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZeroShell 1.0beta11 - Remote Code Execution
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell meta
60RIESGO
abrir ↗Referência✓ VexDay Proof
OpenEMR 2.8.1 - 'fileroot' Remote File Inclusion
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earl
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.asx' 'HREF' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir ↗Referência✓ VexDay Proof
vbzoom 1.x - 'forum.php?MainID' SQL Injection
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - '.chm' Denial of Service (HTML Compiled)
Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and
35RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Stats Generator 2.1.1 - SQL Injection
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft Ajax Portal 3.0 - 'page' SQL Injection
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.asx' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arb
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.