Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RIESGO
abrir ↗Referência✓ VexDay Proof
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
The Bible Portal Project 2.12 - 'destination' File Inclusion
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlueShoes Framework 4.6 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrar
28RIESGO
abrir ↗Referência✓ VexDay Proof
empris r20020923 - 'phormationdir' Remote File Inclusion
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enterprise Payroll Systems 1.1 - 'footer' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier all
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enthrallweb ePhotos 1.0 - 'subLevel2.asp' SQL Injection
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Winlpd 1.2 Build 1076 - Remote Buffer Overflow
Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a requ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (1)
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_videodb 0.3en - Remote File Inclusion
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component Sitemap 2.0.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_hashcash 1.2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier a
23RIESGO
abrir ↗Referência✓ VexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component MoSpray 18RC1 - Remote File Inclusion
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0.4 - 'old_prefix' Blind SQL Injection
SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component User Home Pages 0.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RIESGO
abrir ↗Referência✓ VexDay Proof
Kayako eSupport 2.3.1 - 'subd' Remote File Inclusion
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when regis
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
Open Cubic Player 2.6.0pre6/0.1.10_rc5 - Multiple Local Buffer Overflows
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier
28RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Explorer - '.WMF' CreateBrushIndirect Denial of Service
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP,
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.