Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Carom3D 5.06 - Unicode Buffer Overrun/Denial of Service
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência✓ VexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RIESGO
abrir ↗Referência✓ VexDay Proof
Post Affiliate Pro 3 - 'umprof_status' Blind SQL Injection
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Links Management Application 1.0 - 'lcnt' SQL Injection
SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
TeamCal Pro 2.8.001 - 'app_root' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_downloads - SQL Injection
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_books - 'book_id' SQL Injection
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RIESGO
abrir ↗Referência✓ VexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Myiosoft EasyBookMarker 4 - 'Parent' SQL Injection
SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinOS 4.5.5 - 'gBRootPath' Remote File Inclusion
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Q-Shop 3.5 - 'browse.asp' SQL Injection
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
smeweb 1.4b - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.