Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
BitchX 1.1 Final - MODE Remote Heap Overflow
Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in
28RIESGO
abrir ↗Referência✓ VexDay Proof
RaidenFTPd 2.4 build 3620 - Remote Denial of Service
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service
23RIESGO
abrir ↗Referência✓ VexDay Proof
IndexScript 3.0 - 'parent_id' SQL Injection
SQL injection vulnerability in sug_cat.php in IndexScript 3.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component ownbiblio 1.5.3 - 'catid' SQL Injection
SQL injection vulnerability in the OwnBiblio (com_ownbiblio) component 1.5.3 for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gforge 4.6 rc1 - 'skill_edit' SQL Injection
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPenpals 1.1 - 'mail.php?ID' SQL Injection
SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência✓ VexDay Proof
aflog 1.01 - Cross-Site Scripting / SQL Injection
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBB Plugin Custom Pages 1.0 - SQL Injection
SQL injection vulnerability in pages.php in Custom Pages 1.0 plugin for MyBulletinBoard (MyBB) allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
2532/Gigs 1.2.2 - Arbitrary Database Backup/Download
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple CFNetwork - HTTP Response Denial of Service
The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remot
28RIESGO
abrir ↗Referência✓ VexDay Proof
Cobalt 0.1 - Multiple SQL Injections
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir ↗Referência✓ VexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mooseguy Blog System 1.0 - 'month' SQL Injection
SQL injection vulnerability in blog.php in Mooseguy Blog System (MGBS) 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Auto Listings - 'pg' SQL Injection
SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗Referência✓ VexDay Proof
PreProject Multi-Vendor Shopping Malls - Multiple Vulnerabilities
Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setti
23RIESGO
abrir ↗Referência✓ VexDay Proof
FutureSoft TFTP Server 2000 - Remote Overwrite (SEH)
Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrar
28RIESGO
abrir ↗Referência✓ VexDay Proof
Alstrasoft Forum Pay Per Post Exchange 2.0 - SQL Injection
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Shopping Mall - Insecure Cookie Handling
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Harlandscripts drinks - 'recid' SQL Injection
SQL injection vulnerability in index.php in Five Dollar Scripts Drinks script allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
ModSecurity < 2.5.9 - Remote Denial of Service
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a m
28RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component com_Musica - 'id' SQL Injection
SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência✓ VexDay Proof
Aconon Mail 2004 - Directory Traversal
Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterpr
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Software - 'id' SQL Injection
SQL injection vulnerability in software-description.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flexphpsite 0.0.1 - Authentication Bypass
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is d
23RIESGO
abrir ↗Referência✓ VexDay Proof
Seagull 0.6.3 - 'files' Remote File Disclosure
Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Comodo AntiVirus 2.0 - 'ExecuteStr()' Remote Command Execution
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteS
35RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Gaming Cheats - SQL Injection
SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
SFS EZ Top Sites - SQL Injection
SQL injection vulnerability in topsite.php in Scripts For Sites (SFS) EZ Top Sites allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Galatolo Web Manager 1.3a - Cross-Site Scripting / SQL Injection
SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers t
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.