Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.960VulnCheck XDB 8542Nuclei 4243Metasploit 3472✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência✓ VexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RIESGO
abrir ↗Referência
CVE-2009-4783
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
Oreon 1.2.3 RC4 - '/lang/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência
CVE-2009-4784
SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RIESGO
abrir ↗Referência
CVE-2020-10189
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir ↗Referência✓ VexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir ↗Referência
CVE-2009-4805
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗Referência
CVE-2023-34362
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗Referência
CVE-2026-9294
Edimax BR-6428NS POST Request formWanTcpipSetup buffer overflow
41RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyReports 3.0.11 - 'lib_head.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote att
23RIESGO
abrir ↗Referência
CVE-2026-65710
sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption
41RIESGO
abrir ↗Referência✓ VexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RIESGO
abrir ↗Referência
CVE-2009-4807
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Foro Domus 2.10 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência
CVE-2009-4809
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RIESGO
abrir ↗Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hailboards 1.2.0 - 'phpbb_root_path' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ExoPHPDesk 1.2.1 - 'faq.php' SQL Injection
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cadre PHP Framework - Remote File Inclusion
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Fullaspsite Asp Hosting Sitesi - 'tr' SQL Injection
SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyRing 4.1.3b - 'fichier' Remote File Inclusion
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module Emporium 2.3.0 - SQL Injection
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.