Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Link ADS 1 - 'linkid' SQL Injection
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗Referência✓ VexDay Proof
evilboard 0.1a - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
evilboard 0.1a - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webdevindo-CMS 0.1 - 'hal' SQL Injection
SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir ↗Referência✓ VexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Directory Traversal
Directory traversal vulnerability in formbankcgi.exe/AbfrageForm in Formbankserver 1.9 allows remote attackers to read a
23RIESGO
abrir ↗Referência✓ VexDay Proof
osData 2.08 Modules Php121 - Local File Inclusion
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Rich Textbox Control 6.0-SP6 - 'SaveFile()' Insecure Method
The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary command
28RIESGO
abrir ↗Referência✓ VexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Photo Gallery 1.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authen
23RIESGO
abrir ↗Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência✓ VexDay Proof
evCal Events Calendar - Database Disclosure
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin st_newsletter - SQL Injection
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RIESGO
abrir ↗Referência✓ VexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyCars Automotive - Authentication Bypass
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Virtue Book Store - 'cid' SQL Injection
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component MooFAQ (com_moofaq) - Local File Inclusion
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Jooml
38RIESGO
abrir ↗Referência✓ VexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Digital Data Communications - 'RtspVaPgCtrl' Class Remote Buffer Overflow
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows re
28RIESGO
abrir ↗Referência✓ VexDay Proof
alitalk 1.9.1.1 - Multiple Vulnerabilities
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-Blog 2.0 - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id
23RIESGO
abrir ↗Referência✓ VexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (2)
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.