Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RIESGO
abrir ↗Referência✓ VexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Phorum 3.2.11 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module mx_modsdb 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Po
23RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module WebLinks 2.05 - Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and ear
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Update 2.7 - 'extract()' Authentication Bypass / Shell Injection
Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RIESGO
abrir ↗Referência✓ VexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RIESGO
abrir ↗Referência✓ VexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Aqua CMS - 'Username' SQL Injection
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jamroom 4.0.2 - 't' Local File Inclusion
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASX to MP3 Converter - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗Referência✓ VexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir ↗Referência✓ VexDay Proof
RM Downloader - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RIESGO
abrir ↗Referência✓ VexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RIESGO
abrir ↗Referência✓ VexDay Proof
OpenSSL < 0.9.8i - DTLS ChangeCipherSpec Remote Denial of Service
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RIESGO
abrir ↗Referência✓ VexDay Proof
CRE Loaded 6.2 - 'products_id' SQL Injection
SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
TotalCalendar 2.4 - 'Include' Local File Inclusion
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
e107 < 0.7.15 - 'extended_user_fields' Blind SQL Injection
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and m
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quick.CMS.Lite 0.5 - 'id' SQL Injection
SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.