Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Referência✓ VexDay Proof
Docebo 3.5.0.3 - 'lib.regset.php' Command Execution
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/cla
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ HYIP ACME - 'news.php' SQL Injection
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Toko Instan 7.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Softbiz Banner Exchange Network Script 1.0 - SQL Injection
SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authentica
23RIESGO
abrir ↗Referência✓ VexDay Proof
patBBcode 1.0 - 'bbcodeSource.php' Remote File Inclusion
PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
MPM Chat 2.5 - 'view.php?logi' Local File Inclusion
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗Referência✓ VexDay Proof
Minerva 2.0.8a Build 237 - 'phpbb_root_path' File Inclusion
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mega File Hosting Script 1.2 - 'url' Remote File Inclusion
PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
vsp stats processor 0.45 - 'gamestat.php?gameID' SQL Injection
SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
WEBBDOMAIN Quiz 1.02 - Authentication Bypass
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Banner Management Script - 'id' SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
KnowledgeQuest 2.5 - Arbitrary Add Admin
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome - Carriage Return Null Object Memory Exhaustion
Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoScript 4.0.1.50 - Change Admin Password
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authent
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mega File Hosting Script 1.2 - 'fid' SQL Injection
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authe
23RIESGO
abrir ↗Referência✓ VexDay Proof
OTManager CMS 2.4 - Insecure Cookie Handling
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMI
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
Ixprim 1.2 allows remote attackers to obtain sensitive information via a direct request for kernel/plugins/fckeditor2/ix
23RIESGO
abrir ↗Referência✓ VexDay Proof
SyndeoCMS 2.5.01 - 'cmsdir' Remote File Inclusion
PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninsta
23RIESGO
abrir ↗Referência✓ VexDay Proof
All Club CMS 0.0.2 - Remote Database Configuration Retrieve
All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ax Developer CMS 0.1.1 - 'index.php?module' Local File Inclusion
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Topsites 1.0 - Arbitrary Edit/Add Users
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2
23RIESGO
abrir ↗Referência✓ VexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pag
23RIESGO
abrir ↗Referência✓ VexDay Proof
PeopleAggregator 1.2pre6-release-53 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow
35RIESGO
abrir ↗Referência✓ VexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
eLineStudio Site Composer (ESC) 2.6 and earlier allows remote attackers to obtain sensitive information via a direct req
23RIESGO
abrir ↗Referência✓ VexDay Proof
WonderWare SuiteLink 2.0 - Remote Denial of Service (Metasploit)
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
TinyWebGallery 1.7.6 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScarNews 1.2.1 - 'sn_admin_dir' Local File Inclusion
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.