Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RIESGO
abrir ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Trade 2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RIESGO
abrir ↗Referência✓ VexDay Proof
Distinct TFTP 3.10 - Writable Directory Traversal Execution (Metasploit)
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo
68RIESGO
abrir ↗Referência✓ VexDay Proof
CMS little 0.0.1 - 'term' SQL Injection
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Turnkey Arcade Script - SQL Injection (1)
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Referência✓ VexDay Proof
eWebquiz 8 - Authentication Bypass
SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
ActiveVotes 2.2 - Authentication Bypass
SQL injection vulnerability in register.asp in ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Solar Empire 2.9.1.1 - Blind SQL Injection / Hash Retrieve
SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Membership 2 - Authentication Bypass
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
TxtBlog 1.0 Alpha - Local File Inclusion
Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência✓ VexDay Proof
patBBcode 1.0 - 'bbcodeSource.php' Remote File Inclusion
PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
Opera 9.62 - 'file://' Local Heap Overflow
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file://
35RIESGO
abrir ↗Referência✓ VexDay Proof
Active Bids 3.5 - 'itemID' Blind SQL Injection
SQL injection vulnerability in bidhistory.asp in Active Bids 3.5 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Made Simple 1.4.1 - Local File Inclusion
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft Ajax Portal 3.0 - Authentication Bypass
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Dada Mail Manager 2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for
35RIESGO
abrir ↗Referência✓ VexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Vinagre < 2.24.2 - 'show_error()' Remote Format String (PoC)
Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2
23RIESGO
abrir ↗Referência✓ VexDay Proof
Txx CMS 0.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code v
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHPDJ 0.5 - 'djpage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in djpage.php in PHPDJ 0.5 allows remote attackers to execute arbitrary PHP code
28RIESGO
abrir ↗Referência✓ VexDay Proof
Softbiz Auctions Script - 'product_desc.php' SQL Injection
SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kusaba 1.0.4 - Remote Code Execution (2)
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Realtek Sound Manager (rtlrack.exe 1.15.0.0) - Playlist Buffer Overflow
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.