Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
IntelliTamper 2.07/2.08 Beta 4 - A HREF Remote Buffer Overflow
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.2.0c - Bypass BBCode Cross-Site Scripting Cookie Stealing
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HT
23RIESGO
abrir ↗Referência✓ VexDay Proof
ATutor 1.6.1-pl1 - 'import.php' Remote File Inclusion
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authe
23RIESGO
abrir ↗Referência✓ VexDay Proof
KISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP thr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Particle Blogger 1.2.0 - 'post.php?postid' SQL Injection
SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - 'sid' SQL Injection
SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc i
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apartment Search Script - 'listtest.php' SQL Injection
SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Getacoder clone - 'sb_protype' SQL Injection
SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Datsogallery 1.6 - Blind SQL Injection
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean12 Membership Manager Pro - Authentication Bypass
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
BrewBlogger 2.1.0.1 - Arbitrary Add Admin
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.
23RIESGO
abrir ↗Referência✓ VexDay Proof
PAD Site Scripts 3.6 - Insecure Cookie Handling
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi
23RIESGO
abrir ↗Referência✓ VexDay Proof
RunCMS Newbb_plus 0.92 - Client IP SQL Injection
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component joovideo 1.2.2 - 'id' SQL Injection
SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Classifieds Script 05122008 - SQL Injection
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
FizzMedia 1.51.2 - SQL Injection
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Ignite Gallery 0.8.3 - SQL Injection
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Peel Shopping 3.1 - 'rubid' SQL Injection
SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
VidShare Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RIESGO
abrir ↗Referência✓ VexDay Proof
MultiCart 1.0 - Blind SQL Injection
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
Softbiz Freelancers Script 1 - SQL Injection
Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Help Agent 1.1 - 'content' Local File Inclusion
Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Tribiq CMS 5.0.10a (Windows) - Local File Inclusion
Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and regi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which
23RIESGO
abrir ↗Referência✓ VexDay Proof
Osprey 1.0 - 'GetRecord.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScozNews 1.2.1 - 'mainpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche News 1.x - 'CAT_ID' SQL Injection
SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.