Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Arab Portal 2.1 (Windows) - Remote File Disclosure
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RIESGO
abrir ↗Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash
28RIESGO
abrir ↗Referência✓ VexDay Proof
ChartDirector 4.1 - 'viewsource.php' File Disclosure
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive file
23RIESGO
abrir ↗Referência✓ VexDay Proof
Link Request Contact Form 3.4 - Remote Code Execution
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
PowerPHPBoard 1.00b - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to injec
23RIESGO
abrir ↗Referência✓ VexDay Proof
easysite 2.3 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire
23RIESGO
abrir ↗Referência✓ VexDay Proof
PowerPortal 2.0.13 - 'path' Local Directory Traversal
Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary file
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPLD 3.3 - Blind SQL Injection
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_qu
23RIESGO
abrir ↗Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser
50RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.6 - 'error_log' Safe_mode Bypass
PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_f
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - 'editlink.php' SQL Injection
SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrat
23RIESGO
abrir ↗Referência✓ VexDay Proof
EQdkp 1.3.0 - 'dbal.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Core 2.2 - 'xmlrpc.php' SQL Injection
SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Segue CMS 1.8.4 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled,
35RIESGO
abrir ↗Referência✓ VexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mosaic Commerce - 'cid' SQL Injection
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component DBQuery 1.4.1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe Album Starter 3.2 - Unchecked Local Buffer Overflow
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remot
28RIESGO
abrir ↗Referência✓ VexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RIESGO
abrir ↗Referência✓ VexDay Proof
philboard 1.14 - 'philboard_forum.asp' SQL Injection
SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
CCProxy 6.2 - 'ping' Remote Buffer Overflow
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long addre
28RIESGO
abrir ↗Referência✓ VexDay Proof
Blogator-script 0.95 - 'incl_page' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Blogator-script before 1.01 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Creamotion - 'securite.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
sPHPell 1.01 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual FoxPro 6.0 - 'FPOLE.OCX' Arbitrary Command Execution
Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote a
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.