Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Joomla! Component imagebrowser 0.1.5 rc2 - Directory Traversal
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote atta
43RIESGO
abrir ↗Referência✓ VexDay Proof
E-Shop Shopping Cart Script - 'search_results.php' SQL Injection
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyPBS - 'seasonID' SQL Injection
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Emefa Guestbook 3.0 - Remote Database Disclosure
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
myPHPscripts Login Session 2.0 - Cross-Site Scripting / Database Disclosure
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗Referência✓ VexDay Proof
EFS Easy Chat Server 2.2 - Remote Denial of Service
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RIESGO
abrir ↗Referência✓ VexDay Proof
WebcamXP 5.3.2.375 - Remote File Disclosure
Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Wireshark 1.0.6 - PN-DCP Format String (PoC)
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker
28RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RIESGO
abrir ↗Referência✓ VexDay Proof
IntelliTamper 2.07/2.08 - 'ProxyLogin' Local Stack Overflow
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component 5starhotels - SQL Injection
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent
23RIESGO
abrir ↗Referência✓ VexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Discussion Web 4 - Remote Database Disclosure
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RIESGO
abrir ↗Referência✓ VexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RIESGO
abrir ↗Referência✓ VexDay Proof
clickandemail - SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mediatheka 4.2 - 'lang' Local File Inclusion
Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche Directory - Database Disclosure
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche Articles - Database Disclosure
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
nicLOR CMS - 'sezione_news.php' SQL Injection
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Umer Inc Songs Portal Script - 'id' SQL Injection
SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP-DEV Internal E-Mail System - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlexPHPNews 0.0.6 / PRO - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arb
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.