Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Rat CMS Alpha 2 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
visualpic 0.3.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP
28RIESGO
abrir ↗Referência✓ VexDay Proof
FreshView 7.15 - '.psp' Local Buffer Overflow
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP fi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0
23RIESGO
abrir ↗Referência✓ VexDay Proof
TalkBack 2.2.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joovili 3.0.6 - 'joovili.images.php' Remote File Disclosure
Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metachara
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Gemini Portal 4.7 - Insecure Cookie Handling
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain
23RIESGO
abrir ↗Referência✓ VexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPG.Board 0.0.8Beta2 - Insecure Cookie Handling
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep
23RIESGO
abrir ↗Referência✓ VexDay Proof
XplodPHP AutoTutorials 2.1 - 'id' SQL Injection
SQL injection vulnerability in viewcat.php in XplodPHP AutoTutorials 2.1 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗Referência✓ VexDay Proof
ImageShack Toolbar 4.5.7 - 'FileUploader' Class InsecureMethod
The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69,
23RIESGO
abrir ↗Referência✓ VexDay Proof
PStruh-CZ 1.3/1.5 - 'download.asp' File Disclosure
Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Links 1.3 - 'smarty.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Free PHP VX Guestbook 1.06 - Arbitrary Database Backup
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
Multiple SQL injection vulnerabilities in functions/display_page.func.php in cpCommerce 1.1.0 allow remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
ThinkEdit 1.9.2 - 'render.php' Remote File Inclusion
PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_glo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pie Web M{a_e}sher 0.5.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Colloquy 2.1.3545 - 'INVITE' Format String Denial of Service
Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
DivX Player 6.7.0 - '.srt' File Buffer Overflow (PoC)
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RIESGO
abrir ↗Referência✓ VexDay Proof
Star Articles 6.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Maxum Rumpus 6.0 - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation f
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Classifieds Script - Remote Database Disclosure
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Greetings 2.1 - Insecure Cookie Handling
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the m
23RIESGO
abrir ↗Referência✓ VexDay Proof
BigAnt Server 2.2 - Remote Overflow (SEH)
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RIESGO
abrir ↗Referência✓ VexDay Proof
VBA32 Personal AntiVirus 3.12.8.x - Malformed Archive Denial of Service
The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of servi
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpChess Community Edition 2.0 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpChess Community Edition 2.0 allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.