Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
PHP 4.4.6 - 'cpdf_open()' Local Source Code Disclosure
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensiti
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
VBA32 Personal AntiVirus 3.12.8.x - Malformed Archive Denial of Service
The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of servi
23RIESGO
abrir ↗Referência✓ VexDay Proof
LightBlog 9.5 - 'cp_upload_image.php' Arbitrary File Upload
Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpChess Community Edition 2.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Snort 2.6.1.1/2.6.1.2/2.7.0 - 'fragementation' Remote Denial of Service
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip
23RIESGO
abrir ↗Referência✓ VexDay Proof
BigAnt Server 2.2 - Remote Overflow (SEH)
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
Star Articles 6.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
DivX Player 6.7.0 - '.srt' File Buffer Overflow (PoC)
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RIESGO
abrir ↗Referência✓ VexDay Proof
Libstats 1.0.3 - 'template_csv.php' Remote File Inclusion
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.1 - 'substr_compare()' Information Leak
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
23RIESGO
abrir ↗Referência✓ VexDay Proof
Silentum LoginSys 1.0.0 - Insecure Cookie Handling
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Wordspew - SQL Injection
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPKB Knowledge Base Software 1.5 - 'ID' SQL Injection
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Dating 1.0 - 'view_profile.php' SQL Injection
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pie Web M{a_e}sher 0.5.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Colloquy 2.1.3545 - 'INVITE' Format String Denial of Service
Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
ThinkEdit 1.9.2 - 'render.php' Remote File Inclusion
PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_glo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Classifieds Listings 1.0 - SQL Injection
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpAtm 1.30 - 'downloadfile' Remote File Disclosure
Directory traversal vulnerability in index.php in PHP Advanced Transfer Manager (phpATM) 1.30 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Shadow Premod 2.7.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Weblogicnet - 'files_dir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗Referência✓ VexDay Proof
VicFTPS < 5.0 - 'CWD' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application cras
23RIESGO
abrir ↗Referência✓ VexDay Proof
EVA-Web 1.1 < 2.2 - 'index.php3' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in index.php3 in EVA-Web 1.1 through 2.2 allow remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! / Mambo Component Taskhopper 1.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.