Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
wget 1.10.2 - Unchecked Boundary Condition Denial of Service
The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause
23RIESGO
abrir ↗Referência✓ VexDay Proof
CafeEngine - 'catid' SQL Injection
SQL injection vulnerability in index.php in Easy CafeEngine allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebXell Editor 0.1.3 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Buffer Overflow (PoC)
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RIESGO
abrir ↗Referência✓ VexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.x COM - Safe Mode / disable_functions Bypass
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restricti
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.2 - Multiple Vulnerabilities
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mailist 3.0 - Insecure Backup / Local File Inclusion
Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_q
23RIESGO
abrir ↗Referência✓ VexDay Proof
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
minb 0.1.0 - Remote Code Execution
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência✓ VexDay Proof
BoonEx Ray 3.5 - 'sIncPath' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals i
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB keyword_replacer 1.0 - 'pathToFiles' File Inclusion
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer - MDAC Remote Code Execution (MS06-014)
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RIESGO
abrir ↗Referência✓ VexDay Proof
Etomite CMS 0.6.1 - 'rfiles.php' Remote Command Execution
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RIESGO
abrir ↗Referência✓ VexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
AllMyGuests 0.4.1 - 'cfg_serverpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
chipmunk topsites - Authentication Bypass / Cross-Site Scripting
SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
OllyDBG 1.10 and ImpREC 1.7f - Export Name Buffer Overflow
Stack-based buffer overflow in (1) OllyDBG 1.10 and (2) ImpREC 1.7f allows user-assisted attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMSmelborp Beta - 'user_standard.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashGameScript 1.5.4 - 'index.php?func' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
CrystalPlayer 1.98 - '.mls' Local Buffer Overflow
Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long str
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrato
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyProfiler 0.9.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is en
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'PHP-stats-options.php' Command Execution
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to exe
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.