Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a dire
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Faethon 2.0 - 'mainpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and ma
23RIESGO
abrir ↗Referência✓ VexDay Proof
WFTPD Pro Server 3.25 - Site ADMN Remote Denial of Service
Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service
23RIESGO
abrir ↗Referência✓ VexDay Proof
YNP Portal System 2.2.0 - 'showpage.cgi p' Remote File Disclosure
Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary f
23RIESGO
abrir ↗Referência✓ VexDay Proof
Live for Speed S1/S2/Demo - '.ply' Local Buffer Overflow
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RIESGO
abrir ↗Referência✓ VexDay Proof
TLS - Renegotiation
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir ↗Referência✓ VexDay Proof
SmodBIP 1.06 - aktualnosci zoom SQL Injection
SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Easy-Clanpage 3.0b1 - 'section' Local File Inclusion
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local
23RIESGO
abrir ↗Referência✓ VexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Core 2.1.2 - 'xmlrpc' SQL Injection
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - IPv6-ipcomp Remote kernel Denial of Service (PoC)
The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check th
28RIESGO
abrir ↗Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scribe 0.2 - PHP Remote Code Execution
Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inje
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Live for Speed S1/S2/Demo - '.spr' Local Buffer Overflow
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hummingbird 13.0 - ActiveX Remote Buffer Overflow (PoC)
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quake 3 Engine Client (Windows x86) - CS_ITEms Remote Overflow
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause
23RIESGO
abrir ↗Referência✓ VexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPEasyNews 1.13 RC2 - 'POST' SQL Injection
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hummingbird Deployment Wizard 2008 - Registry Values Creation/Change
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RIESGO
abrir ↗Referência✓ VexDay Proof
APC ActionApps CMS 2.8.1 - Remote File Inclusion
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Activist Mobilization Platform (AMP) 3.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Socketwiz BookMarks 2.0 - 'root_dir' Remote File Inclusion
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Pub Site Directory - 'Directory.php?cat' SQL Injection
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.