Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'DLMFDISK.sy's Local kernel Ring0 SYSTEM
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL r
23RIESGO
abrir ↗Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'LIST' Local Kernel Memory Leak
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RIESGO
abrir ↗Referência✓ VexDay Proof
ZYXEL ZyWALL Quagga/Zebra - 'Default Password' Remote Code Execution
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RIESGO
abrir ↗Referência✓ VexDay Proof
phpComasy 0.8 - 'mod_project_id' SQL Injection
SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpMyNewsletter 0.8 (beta5) - Multiple Vulnerabilities
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification
23RIESGO
abrir ↗Referência✓ VexDay Proof
Internet Download Accelerator 5.2 - Remote Buffer Overflow (PoC)
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RIESGO
abrir ↗Referência✓ VexDay Proof
EDraw Office Viewer Component - Unsafe Method
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions befo
23RIESGO
abrir ↗Referência✓ VexDay Proof
dagger Web engine 23jan2007 - Remote File Inclusion
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows r
45RIESGO
abrir ↗Referência✓ VexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RIESGO
abrir ↗Referência✓ VexDay Proof
WebChat 0.78 - 'login.php?rid' SQL Injection
SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuickTicket 1.2 - 'qti_checkname.php' Local File Inclusion
Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Buddy Zone 1.5 - 'view_sub_cat.php?cat_id' SQL Injection
SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS 2.0.13.2 - 'xoopsOption[nocommon]' Remote Command Execution
mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite varia
23RIESGO
abrir ↗Referência✓ VexDay Proof
workbench 0.11 - 'header.php?path' Remote File Inclusion
PHP remote file inclusion vulnerability in header.php in workbench survival guide 0.11 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Flashgames Module 1.0.1 - SQL Injection
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Monalbum 0.8.7 - Remote Code Execution
Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogMe 3.0 - 'archshow.asp?var' SQL Injection
SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Notepad++ 4.1 (Windows x86) - '.ruby' File Processing Buffer Overflow
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, all
28RIESGO
abrir ↗Referência✓ VexDay Proof
webdesproxy 0.0.1 - GET Remote Buffer Overflow
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involvin
23RIESGO
abrir ↗Referência✓ VexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RIESGO
abrir ↗Referência✓ VexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Explorer - '.GIF' Image Denial of Service
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certa
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RIESGO
abrir ↗Referência✓ VexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Remote Delete File
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.