Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8883Nuclei 4365Metasploit 3493✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
IMGallery 2.5 - Create Uploader Script
users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
VerliAdmin 0.3 - 'language.php' Local File Inclusion
Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
OmniWeb 5.5.1 - JavaScript alert() Remote Format String (PoC)
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application
23RIESGO
abrir ↗Referência✓ VexDay Proof
AllMyVisitors 0.4.0 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RIESGO
abrir ↗Referência✓ VexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
CascadianFAQ 4.1 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RIESGO
abrir ↗Referência✓ VexDay Proof
GuppY 4.5.16 - Remote Command Execution
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dev-C++ 4.9.9.2 - '.CPP' File Parsing Local Stack Overflow (PoC)
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of serv
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hailboards 1.2.0 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ExoPHPDesk 1.2.1 - 'faq.php' SQL Injection
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cadre PHP Framework - Remote File Inclusion
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fullaspsite Asp Hosting Sitesi - 'tr' SQL Injection
SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyRing 4.1.3b - 'fichier' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RIESGO
abrir ↗Referência✓ VexDay Proof
CoD2: DreamStats 4.2 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and ear
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RIESGO
abrir ↗Referência✓ VexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir ↗Referência✓ VexDay Proof
SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Categories hierarchy phpBB Mod 2.1.2 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2
23RIESGO
abrir ↗Referência✓ VexDay Proof
LightRO CMS 1.0 - 'inhalt.php' Remote File Inclusion
PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kisisel Site 2007 - 'tr' SQL Injection
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Alibaba Alipay - Remove ActiveX Remote Code Execution
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScri
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.