Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir ↗Referência✓ VexDay Proof
XLPortal 2.2.4 - 'Search' SQL Injection
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Webquest 2.6 - 'id_actividad' SQL Injection
SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Frontis 3.9.01.24 - 'source_class' SQL Injection
SQL injection vulnerability in bin/aps_browse_sources.php in Frontis 3.9.01.24 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
RSS Simple News - SQL Injection
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple DNS Plus 5.0/4.1 - Remote Denial of Service
Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of servic
23RIESGO
abrir ↗Referência✓ VexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (1)
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
preCMS 1 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple QuickTime 7.5.5 / iTunes 8.0 - Remote Off-by-One Crash
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr
28RIESGO
abrir ↗Referência✓ VexDay Proof
Uebimiau Web-Mail 2.7.10/2.7.2 - Remote File Disclosure
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests,
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPBB2 MODificat 0.2.0 - 'functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote at
28RIESGO
abrir ↗Referência✓ VexDay Proof
Hailboards 1.2.0 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
TOSMO/Mambo 1.4.13a - 'absolute_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and p
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bea Weblogic Apache Connector - Code Execution / Denial of Service
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RIESGO
abrir ↗Referência✓ VexDay Proof
Webdevindo-CMS 0.1 - 'hal' SQL Injection
SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
evilboard 0.1a - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
evilboard 0.1a - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
FirmWorX 0.1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
Miniweb 2.0 - Authentication Bypass
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
2WIRE DSL Router - 'xslt' Denial of Service
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 17
23RIESGO
abrir ↗Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'DeleteXMLFile()' Insecure Method
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RIESGO
abrir ↗Referência✓ VexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Ynews 1.0.0 - 'id' SQL Injection
SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component DT Register - SQL Injection
SQL injection vulnerability in the DT Register (com_dtregister) 2.2.3 component for Joomla! allows remote attackers to e
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.