Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
AuraCMS 2.2 - Remote Add Administrator
Directory traversal vulnerability in index.php in AuraCMS 2.2 allows remote authenticated users to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Exero CMS 1.0.1 - 'theme' Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include a
23RIESGO
abrir ↗Referência✓ VexDay Proof
OtomiGen.x 2.2 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in OtomiGenX 2.2 allow remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
ezcms 1.2 - Blind SQL Injection / Authentication Bypass
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Boite de News 4.0.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
syzygyCMS 0.3 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in SyzygyCMS 0.3 allows remote attackers to include and execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
e107 < 0.75 - 'e107language_e107cookie' Local File Inclusion
Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-CMS 1.0.1 - 'index.php' Local File Inclusion
Multiple directory traversal vulnerabilities in index.php in Mini CMS 1.0.1 allow remote attackers to include and execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
KTP Computer Customer Database CMS 1.0 - Local File Inclusion
Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Absolute Form Processor XE-V 1.5 - Insecure Cookie Handling
Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by settin
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cahier de texte 2.2 - Bypass General Access Protection
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
GEPI 1.4.0 - '/gestion/savebackup.php' Remote File Inclusion
PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions
23RIESGO
abrir ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0.5 - 'day' SQL Injection
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RIESGO
abrir ↗Referência✓ VexDay Proof
snetworks PHP Classifieds 5.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or H
23RIESGO
abrir ↗Referência✓ VexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 1.0.154.43 - Clickjacking
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action th
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebText 0.4.5.2 - Remote Code Execution
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
FTP Explorer 1.0.1 Build 047 - Remote CPU Consumption (Denial of Service)
FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CP
23RIESGO
abrir ↗Referência✓ VexDay Proof
XCMS 1.1 - 'Galerie.php' Local File Inclusion
Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
MODx CMS 0.9.6.2 - Remote File Inclusion / Cross-Site Scripting
PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier,
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPortal 1.0 - Insecure Cookie Handling
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RIESGO
abrir ↗Referência✓ VexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.