Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
PHP-Address Book 4.0.x - Multiple SQL Injections
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cahier de texte 2.2 - Bypass General Access Protection
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
OxYProject 0.85 - 'edithistory.php' Remote Code Execution
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Micro CMS 0.3.5 - 'microcms_path' Remote File Inclusion
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0.5 - 'day' SQL Injection
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RIESGO
abrir ↗Referência✓ VexDay Proof
ASP AutoDealer - Remote Database Disclosure
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JMovies 1.1 - 'id' SQL Injection
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP Software Update - 'Hpufunction.dll 4.0.0.1' Insecure Method
Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
metajour 2.1 - 'system_path' Remote File Inclusion
PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
AspWebCalendar 4.5 - 'eventid' SQL Injection
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the us
23RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.2.8 - 'id_document' Blind SQL Injection
SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
XGuestBook 2.0 - Authentication Bypass
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
wPortfolio 0.3 - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to
28RIESGO
abrir ↗Referência✓ VexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zix Forum 1.12 - 'layid' SQL Injection
SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
CubeCart 3.0.6 - Remote Command Execution
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apollo 37zz - '.m3u' Local Heap Overflow (PoC)
Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and p
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Auction 6.2.1 - 'classifide_ad.php' SQL Injection
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Xe webtv - 'id' Blind SQL Injection
SQL injection vulnerability in the Xe webtv (com_xewebtv) component for Joomla! allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
inertianews 0.02b - 'inertianews_main.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
EQdkp 1.3.1 - 'Referer Spoof' Remote Database Backup
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an adm
23RIESGO
abrir ↗Referência✓ VexDay Proof
AcmlmBoard 1.A2 - 'pow' SQL Injection
SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPThai.Net WebBoard 6.0 - SQL Injection
SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.