Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
S-Gastebuch 1.5.3 - 'gb_pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ProjectButler 0.8.4 - 'rootdir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quate CMS 0.3.4 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary director
23RIESGO
abrir ↗Referência✓ VexDay Proof
LAN Management System (LMS) 1.9.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remo
35RIESGO
abrir ↗Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
Directory traversal vulnerability in admin.php in pL-PHP beta 0.9 allows remote attackers to include and execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Local File Inclusion / Code Execution
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 all
23RIESGO
abrir ↗Referência✓ VexDay Proof
POWERGAP 2003 - 's0x.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via
28RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir ↗Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check
23RIESGO
abrir ↗Referência✓ VexDay Proof
Weatimages 1.7.1 - ini[langpack] Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RIESGO
abrir ↗Referência✓ VexDay Proof
verlihub 0.9.8d-RC2 - Remote Command Execution
The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlie
23RIESGO
abrir ↗Referência✓ VexDay Proof
HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component zOOm Media Gallery 2.5 Beta 2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_jim 1.0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmodCMS 2.10 - Slownik ssid SQL Injection
SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
vm Watermark for Gallery 0.4.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for
23RIESGO
abrir ↗Referência✓ VexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenGoo 1.1 - Local File Inclusion
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RIESGO
abrir ↗Referência✓ VexDay Proof
cattaDoc 2.21 - 'download2.php?fn1' Remote File Disclosure
Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Beryo 2.0 - 'downloadpic.php?chemin' Remote File Disclosure
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
TLS - Renegotiation
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir ↗Referência✓ VexDay Proof
SmodBIP 1.06 - aktualnosci zoom SQL Injection
SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to inclu
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.