Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Ciberia Content Federator 1.0.1 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in socios/maquetacion_socio.php (members/maquetacion_member.php) in Ciberia Cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
acFTP FTP Server 1.5 - 'REST/PBSZ' Remote Denial of Service
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) P
23RIESGO
abrir ↗Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication
23RIESGO
abrir ↗Referência✓ VexDay Proof
Calendar MX BASIC 1.0.2 - 'ID' SQL Injection
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
myPHPNuke Module My_eGallery 2.5.6 - 'basepath' Remote File Inclusion
PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN
23RIESGO
abrir ↗Referência✓ VexDay Proof
MTCMS 2.0 - '/admin/admin_settings.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
SH-News 0.93 - 'misc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb ePages - 'actualpic.asp' SQL Injection
SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eCars 1.0 - 'types.asp' SQL Injection
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dragon Business Directory 3.01.12 - 'ID' SQL Injection
SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search D
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eJobs - 'newsdetail.asp' SQL Injection
SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ananda Real Estate 3.4 - 'agent' SQL Injection
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier all
23RIESGO
abrir ↗Referência✓ VexDay Proof
Bubla 1.0.0rc2 - '/bu/process.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
b2 Blog 0.5 - 'b2verifauth.php' Remote File Inclusion
PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
aFAQ 1.0 - 'faqDsp.asp?catcode' SQL Injection
SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB2 Plus 1.53 - Acronym Mod SQL Injection
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
wywo inout board 1.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
RealPlayer 10.5 'ierpplug.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASPTicker 1.0 - Authentication Bypass
SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RIESGO
abrir ↗Referência✓ VexDay Proof
AIDeX Mini-WebServer 1.1 - Remote Crash (Denial of Service)
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RIESGO
abrir ↗Referência✓ VexDay Proof
SoftArtisans SAFileUp 5.0.14 - 'viewsrc.asp' Script Source Disclosure
Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RIESGO
abrir ↗Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.