Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência
CVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RIESGO
abrir ↗Referência✓ VexDay Proof
ScriptMagix Recipes 2.0 - 'index.php?catid' SQL Injection
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência
CVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RIESGO
abrir ↗Referência✓ VexDay Proof
Active Photo Gallery - 'catid' SQL Injection
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Link Engine - 'default.asp?catid' SQL Injection
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a
23RIESGO
abrir ↗Referência
CVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke Module splattforum 4.0 RC1 - Local File Inclusion
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClassWeb 2.0.3 - 'BASE' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr
23RIESGO
abrir ↗Referência
CVE-2017-17575
FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
PortailPhp 2.0 - 'idnews' SQL Injection
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Referência
CVE-2017-17576
FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se
23RIESGO
abrir ↗Referência✓ VexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component RWCards 2.4.3 - SQL Injection
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Active Trade 2 - 'catid' SQL Injection
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pathos CMS 0.92-2 - 'warn.php' Remote File Inclusion
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attac
23RIESGO
abrir ↗Referência
CVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência
CVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Battle.net Clan Script for PHP 1.5.1 - SQL Injection
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application cr
28RIESGO
abrir ↗Referência
CVE-2017-17580
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows - '.hlp' Local HEAP Overflow (PoC)
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a cr
28RIESGO
abrir ↗Referência
CVE-2017-17580
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Beryo 2.0 - 'downloadpic.php?chemin' Remote File Disclosure
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows rem
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.