Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Recipe 1.2 - Insecure Cookie Handling
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RIESGO
abrir ↗Referência✓ VexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gall
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_funct
23RIESGO
abrir ↗Referência✓ VexDay Proof
WSN Guest 1.23 - 'Search' SQL Injection
SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpAuction GPL Enhanced 2.51 - 'profile.php' SQL Injection
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
PowerNews 2.5.4 - 'newsid' SQL Injection
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
Rising AntiVirus Online Scanner - Insecure Method Flaw
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner all
28RIESGO
abrir ↗Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
events Calendar 1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Ca
23RIESGO
abrir ↗Referência✓ VexDay Proof
YapBB 1.2 - 'forumID' Blind SQL Injection
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
webSPELL 4.2.0e - 'page' Blind SQL Injection
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to inc
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPBasket - 'pro_id' SQL Injection
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hex Workshop 6.0 - '.hex' Local Code Execution
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RIESGO
abrir ↗Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component CopperminePhotoGalery - Remote File Inclusion
PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier f
23RIESGO
abrir ↗Referência✓ VexDay Proof
z-breaknews 2.0 - 'single.php' SQL Injection
SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS Ez Forum - SQL Injection
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
PollHelper - Remote Configuration File Disclosure
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to downloa
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod Members CV (job) 1.0 - SQL Injection
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is d
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod E-Cart 1.3 - 'items.php' SQL Injection
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Musoo 0.21 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RIESGO
abrir ↗Referência✓ VexDay Proof
NEPT Image Uploader 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader
23RIESGO
abrir ↗Referência✓ VexDay Proof
PA168 Chipset IP Phones - Weak Session Management
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RIESGO
abrir ↗Referência✓ VexDay Proof
Remote Display Dev kit 1.2.1.0 - 'RControl.dll' Denial of Service
Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of
23RIESGO
abrir ↗Referência✓ VexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.