Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.226exploits catalogados
36.422CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 23.022GitHub PoC 15.028VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Postcast Server Pro 3.0.61 / Quiksoft EasyMail - 'emsmtp.dll 6.0.1' Remote Buffer Overflow
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RIESGO
abrir ↗Referência✓ VexDay Proof
MWOpen E-Commerce - 'leggi_commenti.asp' SQL Injection
SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
eNetman 20050830 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code
35RIESGO
abrir ↗Referência✓ VexDay Proof
Move Networks Quantum Streaming Player - Remote Overflow (SEH)
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie0705100
28RIESGO
abrir ↗Referência✓ VexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft SQL Server - Distributed Management Objects Buffer Overflow
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir ↗Referência✓ VexDay Proof
WebED 0.8999a - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers
35RIESGO
abrir ↗Referência✓ VexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpRealty 0.02 - 'MGR' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP cod
35RIESGO
abrir ↗Referência✓ VexDay Proof
RW::Download 2.0.3 lite - 'index.php?dlid' SQL Injection
Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Studio 6.0 - 'VBTOVSI.dll 1.0.0.0' File Overwrite
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1
28RIESGO
abrir ↗Referência✓ VexDay Proof
X-Cart - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component joom12pic 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla
28RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.0 - 'login.php' SQL Injection
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chupix CMS 0.2.3 - 'download.php' Remote File Disclosure
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overw
23RIESGO
abrir ↗Referência✓ VexDay Proof
Xforum 1.4 - 'topic' SQL Injection
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
DomPHP 0.81 - Remote Add Administrator
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foojan Wms 1.0 - 'story' SQL Injection
SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Easysitenetwork Recipe - 'categoryId' SQL Injection
SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liquid-Silver CMS 0.1 - 'update' Local File Inclusion
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RIESGO
abrir ↗Referência✓ VexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
ActiveKB KnowledgeBase 2.x - 'catId' SQL Injection
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Links 1.3 - 'id' SQL Injection
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_downloads - SQL Injection
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
FaceBook PhotoUploader - 'ImageUploader4.ocx 4.5.57.0' Remote Buffer Overflow
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0,
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.