Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
CaLogic Calendars 1.2.2 - 'langsel' SQL Injection
SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.9.8a - Web UI 'input' Remote Denial of Service
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via
23RIESGO
abrir ↗Referência✓ VexDay Proof
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RIESGO
abrir ↗Referência✓ VexDay Proof
Eudora 7.1.0.9 - IMAP FLAGS Remote Overwrite (SEH)
Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a lon
23RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeStyle Wiki 3.6.2 - 'user.dat' Password Disclosure
FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access contr
23RIESGO
abrir ↗Referência✓ VexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RIESGO
abrir ↗Referência✓ VexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
MojoJobs - Blind SQL Injection
SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RIESGO
abrir ↗Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Joomlaradio 5.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f
35RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dev-C++ 4.9.9.2 - '.CPP' File Parsing Local Stack Overflow (PoC)
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of serv
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebSihirbazi 5.1.1 - 'pageid' SQL Injection
Multiple SQL injection vulnerabilities in websihirbazi 5.1.1 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component mediaslide - 'albumnum' Blind SQL Injection
SQL injection vulnerability in index.php in the MediaSlide (com_mediaslide) 0.5 component for Joomla! allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Technote 7.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when registe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Acajoom 1.1.5 - SQL Injection
SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inje
23RIESGO
abrir ↗Referência✓ VexDay Proof
Elecard AVC HD player - '.m3u' / '.xpl' Local Stack Overflow (PoC)
Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClickAuction - Authentication Bypass
SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Job Script 2.0 - Arbitrary Change Admin Password
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo
23RIESGO
abrir ↗Referência✓ VexDay Proof
SkaDate Online 5.0/6.0 - Remote File Disclosure
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow re
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyNews 4.2.2 - 'themefunc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.