Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
PHP Webquest 2.6 - Get Database Credentials
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RIESGO
abrir ↗Referência✓ VexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi
23RIESGO
abrir ↗Referência✓ VexDay Proof
PowerStrip 3.84 - 'pstrip.sys' Local Privilege Escalation
The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local
23RIESGO
abrir ↗Referência✓ VexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
HotScripts Clone Script - SQL Injection
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module xhresim - SQL Injection
SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir ↗Referência✓ VexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Membership 2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RIESGO
abrir ↗Referência✓ VexDay Proof
TlGuestBook 1.2 - Insecure Cookie Handling
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBo
23RIESGO
abrir ↗Referência✓ VexDay Proof
mini-pub 0.3 - Local Directory Traversal / File Disclosure
Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list a
23RIESGO
abrir ↗Referência✓ VexDay Proof
nuseo PHP enterprise 1.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when registe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RIESGO
abrir ↗Referência✓ VexDay Proof
EncapsCMS 0.3.6 - '/core/core.php' Remote File Inclusion
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RIESGO
abrir ↗Referência✓ VexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir ↗Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthusiast 3.1.4 - 'show_joined.php' Remote File Inclusion
PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RIESGO
abrir ↗Referência✓ VexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Local Classifieds - Authentication Bypass
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a dir
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.