Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
SezHoo 0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
TFT Gallery 0.10 - Password Disclosure
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
ESPG (Enhanced Simple PHP Gallery) 1.72 - File Disclosure
Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyDesk 1.0 Beta - 'viewticket.php' Local File Inclusion
Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Flash Image Gallery - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtga
23RIESGO
abrir ↗Referência✓ VexDay Proof
Social Engine 2.0 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mcafee EPO 4.0 - 'FrameworkService.exe' Remote Denial of Service
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestra
23RIESGO
abrir ↗Referência✓ VexDay Proof
EasyMail MessagePrinter Object - 'emprint.dll 6.0.1.0' Remote Buffer Overflow
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail
23RIESGO
abrir ↗Referência✓ VexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir ↗Referência✓ VexDay Proof
RGameScript Pro - 'page.php?id' Remote File Inclusion
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir ↗Referência✓ VexDay Proof
BS.Player 2.27 Build 959 - '.srt' File Buffer Overflow (PoC)
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JoomlaXplorer 1.6.2 - Remote s
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 an
23RIESGO
abrir ↗Referência✓ VexDay Proof
CS-Gallery 2.0 - 'index.php?album' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir ↗Referência✓ VexDay Proof
ISPworker 1.21 - 'download.php' Remote File Disclosure
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPPortal 3.1.1 - 'downloadid' SQL Injection
Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashBlog - 'articulo_id' SQL Injection
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Module NoMoKeTos Rules 0.0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module fo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RIESGO
abrir ↗Referência✓ VexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RIESGO
abrir ↗Referência✓ VexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.