Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
XOOPS Module wfquotes 1.0 - SQL Injection
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
NoAh 0.9 pre 1.2 - 'mfa_theme.php' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Monalbum 0.8.7 - Remote Code Execution
Static code injection vulnerability in admin/admin_configuration.php in Monalbum 0.8.7 allows remote authenticated users
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogMe 3.0 - 'archshow.asp?var' SQL Injection
SQL injection vulnerability in archshow.asp in BlogMe 3.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
BitchX 1.1-final - 'EXEC' Remote Command Execution
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
SonicWALL SSL-VPN - 'NeLaunchCtrl' ActiveX Control Remote Command Execution
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RIESGO
abrir ↗Referência✓ VexDay Proof
Sony CONNECT Player 4.x - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Referência✓ VexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jakarta Slide 2.1 RC1 - Remote File Disclosure
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
Adult Directory - 'cat_id' SQL Injection
SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Seditio CMS 121 - 'pfs.php' Arbitrary File Upload
Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS Forum Module - SQL Injection
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Envolution 1.1.0 - 'topic' SQL Injection
SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Blue Dragon CMS 3.0.0 - SQL Injection
SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP blue dragon CMS 3.0.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 all
35RIESGO
abrir ↗Referência✓ VexDay Proof
Pixlie 1.7 - 'pixlie.php?root' Remote File Disclosure
pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote d
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ncaster 1.7.2 - 'archive.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to
45RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Webring Website Script - 'category.php?cat' SQL Injection
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Basic 6.0 - VBP_Open OLE Local CodeExec
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual Basic Enterprise 6.0 SP6 - Code Execution
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Visual FoxPro 6.0 - FPOLE.OCX 6.0.8450.0 Remote (PoC)
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the
35RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft SQL Server - Distributed Management Objects Buffer Overflow
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir ↗Referência✓ VexDay Proof
Vantage Linguistics AnswerWorks 4 - API ActiveX Control Buffer Overflow
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Van
35RIESGO
abrir ↗Referência✓ VexDay Proof
WebED 0.8999a - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers
35RIESGO
abrir ↗Referência✓ VexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir ↗Referência✓ VexDay Proof
X-Cart - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Webquest 2.5 - 'id_actividad' SQL Injection
SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.