Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Active Trade 2 - 'catid' SQL Injection
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Rha7 Downloads 1.0 - 'visit.php' SQL Injection
SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.3 - Remote Code Execution
SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Module Arcade 1.0 - 'cid' SQL Injection
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module PopnupBlog 2.52 - 'postid' Blind SQL Injection
SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Module topliste 1.0 - 'cid' SQL Injection
SQL injection vulnerability in index.php in the Topliste 1.0 module for PHP-Fusion allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
AROUNDMe 0.7.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in barnraiser AROUNDMe 0.7.7 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Weatimages 1.7.1 - ini[langpack] Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Weatimages 1.7.1 and earlier, when weatimages.ini is missing, al
23RIESGO
abrir ↗Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check
23RIESGO
abrir ↗Referência✓ VexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.5 - 'calendar.php' Blind SQL Injection
SQL injection vulnerability in calendar.php in MyBB (aka MyBulletinBoard) 1.2.5 and earlier allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kodak Image Viewer - TIF/TIFF Code Execution (MS07-055)
Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote at
35RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RIESGO
abrir ↗Referência✓ VexDay Proof
Adobe Photoshop CS2 / CS3 - '.bmp' Local Buffer Overflow
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attac
35RIESGO
abrir ↗Referência✓ VexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module MX Shotcast 1.0 RC2 - 'getinfo1.php' Remote File Inclusion
PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Papoo 3.02 - kontakt menuid SQL Injection
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
JulmaCMS 1.4 - 'file.php' Remote File Disclosure
Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arb
28RIESGO
abrir ↗Referência✓ VexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gall
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.