Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
AJ HYIP ACME - 'comment.php' SQL Injection
Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
Zeeways ZeeJobsite 2.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated user
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Content 1.0.0 - 'itemID' SQL Injection
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component yvComment 1.16 - Blind SQL Injection
SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (1)
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RIESGO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (2)
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nokia e90/n82 (s60v3) - Remote Denial of Service
Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause
23RIESGO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow (2)
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RIESGO
abrir ↗Referência✓ VexDay Proof
JAMM CMS - 'id' Blind SQL Injection
SQL injection vulnerability in index.php in JAMM CMS allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗Referência✓ VexDay Proof
CKGold Shopping Cart 2.5 - 'category_id' SQL Injection
SQL injection vulnerability in item.php in CartKeeper CKGold Shopping Cart 2.5 and 2.7 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
RevokeBB 1.0 RC11 - 'Search' SQL Injection
SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via un
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_pcchess - Blind SQL Injection
SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyMarket 1.72 - Blind SQL Injection
SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discuz! 6.x/7.x - Remote Code Execution
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RIESGO
abrir ↗Referência✓ VexDay Proof
LE.CMS 1.4 - Arbitrary File Upload
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload a
23RIESGO
abrir ↗Referência✓ VexDay Proof
IGSuite 3.2.4 - Reverse Shell / Blind SQL Injection
SQL injection vulnerability in cgi-bin/igsuite in IGSuite 3.2.4 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in index.php in Traindepot 0.1 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir ↗Referência✓ VexDay Proof
Downline Goldmine Category Addon - SQL Injection
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗Referência✓ VexDay Proof
Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution
modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer
23RIESGO
abrir ↗Referência✓ VexDay Proof
traindepot 0.1 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the search module in Traindepot 0.1 allows remote attackers to inject arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
XChat 2.8.7b - 'URI Handler' Remote Code Execution (Internet Explorer 6/7)
Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Easy Webstore 1.2 - SQL Injection
SQL injection vulnerability in index.php in Easy Webstore 1.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.