Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.594Exploit-DB 24.485GitHub PoC 15.871VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
postecards - SQL Injection / File Disclosure
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apache Geronimo 2.1.3 - Multiple Directory Traversal Vulnerabilities
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1
35RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
PozScripts Business Directory Script - 'cid' SQL Injection
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a craft
23RIESGO
abrir ↗Referência✓ VexDay Proof
Musoo 0.21 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
icblogger 2.0 - 'YID' SQL Injection
SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência✓ VexDay Proof
WM Downloader - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
JW Player - 'playerready' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe Shockwave - 'ShockwaveVersion()' Stack Overflow (PoC)
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a den
35RIESGO
abrir ↗Referência✓ VexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in t
23RIESGO
abrir ↗Referência✓ VexDay Proof
jPORTAL 2.3.1 - 'articles.php' SQL Injection
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash
28RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8b5 - 'msg_id' SQL Injection
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earli
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
SoftArtisans SAFileUp 5.0.14 - 'viewsrc.asp' Script Source Disclosure
Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shop Script Pro 2.12 - SQL Injection
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Arab Portal 2.1 (Windows) - Remote File Disclosure
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'directory.php' SQL Injection
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple
28RIESGO
abrir ↗Referência✓ VexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Symantec BackupExec Calendar Control - 'PVCalendar.ocx' Remote Buffer Overflow
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the schedul
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.