Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Enthrallweb emates 1.0 - 'newsdetail.asp' SQL Injection
SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP Module ConcoursPhoto 2.0 - 'C_ID' SQL Injection
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Akamai Download Manager < 2.2.3.7 - ActiveX Remote Download
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force
28RIESGO
abrir ↗Referência✓ VexDay Proof
Prozilla Hosting Index - 'id' SQL Injection
SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sabros.us 1.75 - 'thumbnails.php' Remote File Disclosure
Directory traversal vulnerability in thumbnails.php in sabros.us 1.75 allows remote attackers to read arbitrary files vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
rdesktop 1.5.0 - 'process_redirect_pdu()' BSS Overflow (PoC)
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitr
28RIESGO
abrir ↗Referência✓ VexDay Proof
BosClassifieds 3.0 - 'index.php' SQL Injection
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
ForumApp 3.3 - Remote Database Disclosure
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
KsIRC 1.3.12 - 'PRIVMSG' Remote Buffer Overflow (PoC)
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to a
28RIESGO
abrir ↗Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RIESGO
abrir ↗Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RIESGO
abrir ↗Referência✓ VexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir ↗Referência✓ VexDay Proof
724CMS 4.01 Enterprise - 'index.php' SQL Injection
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
iScripts Socialware - 'id' SQL Injection
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Blog PixelMotion - 'categorie' SQL Injection
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
PIGMy-SQL 1.4.1 - 'getdata.php' Blind SQL Injection
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficien
23RIESGO
abrir ↗Referência✓ VexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RIESGO
abrir ↗Referência✓ VexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit)
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗Referência✓ VexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
pNews 2.08 - 'shownews' SQL Injection
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.