Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
ItCMS 1.9 - 'boxpop.php' Remote Code Execution
Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inje
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Jokesite 2.0 - 'cat_id' SQL Injection
SQL injection vulnerability in jokes_category.php in PHP-Jokesite 2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Samsung DVR SHR2040 - HTTPd Remote Denial of Service Denial of Service (PoC)
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HT
23RIESGO
abrir ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Destar 0.2.2-5 - Arbitrary Add New User
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Siemens C450IP/C475IP - Remote Denial of Service
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and dev
23RIESGO
abrir ↗Referência✓ VexDay Proof
Page Manager CMS 2006-02-04 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RIESGO
abrir ↗Referência✓ VexDay Proof
living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
R2K Gallery 1.7 - 'galeria.php?lang2' Local File Inclusion
Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashChat 4.5.7 - 'aedating4CMS.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Membership 2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by
23RIESGO
abrir ↗Referência✓ VexDay Proof
Distinct TFTP 3.10 - Writable Directory Traversal Execution (Metasploit)
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo
68RIESGO
abrir ↗Referência✓ VexDay Proof
snap - seccomp BBlacklist for TIOCSTI can be Circumvented
Snapd seccomp filter TIOCSTI ioctl bypass
33RIESGO
abrir ↗Referência✓ VexDay Proof
eIQnetworks ESA SEARCHREPORT - Remote Overflow (Metasploit)
Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
PolDoc CMS 0.96 - 'download_file.php' File Disclosure
Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP User Engine .NET - Remote Database Disclosure
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Easy News Content Management - Database Disclosure
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir ↗Referência✓ VexDay Proof
MX-System 2.7.3 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in MxBB (aka MX-System) Portal 2.7.3 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Flowchart ActiveX Control 2.0 - Insecure Method
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.