Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RIESGO
abrir ↗Referência✓ VexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RIESGO
abrir ↗Referência✓ VexDay Proof
C6 Messenger - ActiveX Remote Download and Execute
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force
50RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin BackUpWordPress 0.4.2b - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow
35RIESGO
abrir ↗Referência✓ VexDay Proof
Bloggie Lite 0.0.2 Beta - Insecure Cookie Handling / SQL Injection
SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ace-FTP Client 1.24a - Remote Buffer Overflow (PoC)
Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long re
23RIESGO
abrir ↗Referência✓ VexDay Proof
GeometriX Download Portal - 'down_indir.asp?id' SQL Injection
SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
MaxCMS 2.0 - '/inc/ajax.asp' SQL Injection
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
FTP Now 2.6 Server - Response Remote Crash (PoC)
Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to caus
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RIESGO
abrir ↗Referência✓ VexDay Proof
LightOpenCMS 0.1 - 'id' SQL Injection
SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component AlphaUserPoints - SQL Injection
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) compo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Real Player - 'rmoc3260.dll' ActiveX Control Remote Code Execution
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RIESGO
abrir ↗Referência✓ VexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
DFD Cart 1.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allo
35RIESGO
abrir ↗Referência✓ VexDay Proof
FeedMon 2.7.0.0 - outline Tag Buffer Overflow (PoC)
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RIESGO
abrir ↗Referência✓ VexDay Proof
DevelopItEasy Membership System 1.3 - Authentication Bypass
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft SQL Server - Distributed Management Objects 'sqldmo.dll' Buffer Overflow (PoC)
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir ↗Referência✓ VexDay Proof
WebDesktop 0.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP cod
35RIESGO
abrir ↗Referência✓ VexDay Proof
CuteNews 1.1.1 - 'html.php' Remote Code Execution
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute
35RIESGO
abrir ↗Referência✓ VexDay Proof
PicoFlat CMS 0.4.14 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.6.1 - 'module_pages_site.php' Local File Inclusion
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to i
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPSlash 0.8.1.1 - Remote Code Execution
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary P
35RIESGO
abrir ↗Referência✓ VexDay Proof
VIDEOSCRIPT.us - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Agares ThemeSiteScript 1.0 - 'loadadminpage' Remote File Inclusion
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RIESGO
abrir ↗Referência✓ VexDay Proof
TikiWiki 1.9.8 - Remote PHP Injection
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.