Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir ↗Referência✓ VexDay Proof
Check New 4.52 - SQL Injection
SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe Reader 8.1.4/9.1 - 'GetAnnots()' Remote Code Execution
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RIESGO
abrir ↗Referência✓ VexDay Proof
fipsForum 2.6 - 'default2.asp' SQL Injection
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple PHP Blog 0.4.7.1 - Remote Command Execution
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RIESGO
abrir ↗Referência✓ VexDay Proof
Integramod 1.4.x - Insecure Directory Download Database
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
DD-WRT HTTPd Daemon/Service - Remote Command Execution
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mercury/32 Mail SMTPD - Remote Stack Overrun (PoC)
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, all
50RIESGO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Grabit 1.7.2 Beta 3 - '.nzb' Local Buffer Overflow (SEH)
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Downline Goldmine paidversion - SQL Injection
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗Referência✓ VexDay Proof
Downline Goldmine newdownlinebuilder - SQL Injection
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RIESGO
abrir ↗Referência✓ VexDay Proof
Downline Goldmine Category Addon - SQL Injection
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Real Estate Listings - 'search.php' SQL Injection
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
FipsCMS 4.5 - 'index.asp' SQL Injection
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RIESGO
abrir ↗Referência✓ VexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zeeways ZeeJobsite 2.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated user
23RIESGO
abrir ↗Referência✓ VexDay Proof
Diesel Joke Site - 'picture_category.php' SQL Injection
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
addalink 4 - 'category_id' SQL Injection
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled
23RIESGO
abrir ↗Referência✓ VexDay Proof
X10media Mp3 Search Engine 1.5.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
μTorrent (uTorrent) / BitTorrent WebIU HTTP 1.7.7/6.0.1 - Range header Denial of Service
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyPHP Forum 3.0 - 'Final' SQL Injection
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.