Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Referência✓ VexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RIESGO
abrir ↗Referência✓ VexDay Proof
PA168 Chipset IP Phones - Weak Session Management
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RIESGO
abrir ↗Referência✓ VexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RIESGO
abrir ↗Referência✓ VexDay Proof
bwired - 'index.php?newsID' SQL Injection
SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the new
23RIESGO
abrir ↗Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe
35RIESGO
abrir ↗Referência✓ VexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ipswitch WS_FTP Server with SSH 6.1.0.0 - Remote Buffer Overflow (PoC)
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of servic
28RIESGO
abrir ↗Referência✓ VexDay Proof
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module mx_tinies 1.3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 all
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Stats 0.1.9.1b - 'ip' SQL Injection
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Clansys 1.1 (showid) - SQL Injection
SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Invision Power Board 2.1.4 - Register Users Denial of Service
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp
23RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RIESGO
abrir ↗Referência✓ VexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
4Images 1.7.1 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
iPrimal Forums - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free File Hosting 1.1 - 'forgot_pass.php' File Inclusion
PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpDynaSite 3.2.2 - 'racine' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.