Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
phpinv 0.8.0 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
FireAnt 1.3 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗Referência✓ VexDay Proof
LanSuite 3.3.2 - 'design' Local File Inclusion
Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Globsy 1.0 - Remote File Rewriting
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scriptsez Mini Hosting Panel - 'members.php' Local File Inclusion
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP
23RIESGO
abrir ↗Referência✓ VexDay Proof
Libra PHP File Manager 1.18 - Insecure Cookie Handling
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the
23RIESGO
abrir ↗Referência✓ VexDay Proof
PAD Site Scripts 3.6 - Arbitrary Database Backup
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
VT-Auth 1.0 - 'zHk8dEes3.txt' File Disclosure
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pritlog 0.4 - 'Filename' Remote File Disclosure
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScriptMagix Jokes 2.0 - 'index.php?catid' SQL Injection
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Reviews Script 1.0 - Arbitrary Delete User
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct reque
23RIESGO
abrir ↗Referência✓ VexDay Proof
Meto Forum 1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sisplet CMS 2008-01-24 - 'id' SQL Injection
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS MAXSITE Component Guestbook - Remote Command Execution
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
MauryCMS 0.53.2 - Arbitrary File Upload
SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlexPHPNews 0.0.5 - 'newsid' SQL Injection
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
myPHPCalendar 10192000b - 'cal_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir ↗Referência✓ VexDay Proof
MeGaCheatZ 1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Download 1.03 - Arbitrary Change Administrator Account
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Koschtit Image Gallery 1.82 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RIESGO
abrir ↗Referência✓ VexDay Proof
XPOZE Pro 3.06 - 'uid' SQL Injection
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.