Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
PHPKB Knowledge Base Software 1.5 - 'ID' SQL Injection
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ Dating 1.0 - 'view_profile.php' SQL Injection
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
Esqlanelapse Software Project 2.6.2 - Insecure Cookie Handling
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enomb
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência✓ VexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a log
23RIESGO
abrir ↗Referência✓ VexDay Proof
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
RealPlayer 11 - '.au' Denial of Service
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Media Player - '.AIFF' Divide By Zero Exception Denial of Service (PoC)
Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a cert
28RIESGO
abrir ↗Referência✓ VexDay Proof
PIGMy-SQL 1.4.1 - 'getdata.php' Blind SQL Injection
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
plxAutoReminder 3.7 - 'id' SQL Injection
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Rat CMS Alpha 2 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoScript 4.0.1.50 - Change Admin Password
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authent
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome - Carriage Return Null Object Memory Exhaustion
Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
KnowledgeQuest 2.5 - Arbitrary Add Admin
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vantage Linguistics AnswerWorks 4 - API ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Van
35RIESGO
abrir ↗Referência✓ VexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Web Calendar 4.1 - Blind SQL Injection
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
STWC-Counter 3.4.0 - 'downloadcounter.php' Remote File Inclusion
PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in
23RIESGO
abrir ↗Referência✓ VexDay Proof
Admin Phorum 3.3.1a - 'del.php?include_path' Remote File Inclusion
PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Friendly Technologies - 'fwRemoteCfg.dll' ActiveX Remote Buffer Overflow
Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPo
23RIESGO
abrir ↗Referência✓ VexDay Proof
X10media Mp3 Search Engine 1.6 - Remote File Disclosure
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.