Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.587exploits catalogados
35.644CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.428GitHub PoC 14.268VulnCheck XDB 8663Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.367 exploits
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir ↗Referência✓ VexDay Proof
NuclearBB Alpha 2 - 'ROOT_PATH' Remote File Inclusion
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e
35RIESGO
abrir ↗Referência✓ VexDay Proof
X-Cart - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir ↗Referência✓ VexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Boa 0.93.15 - HTTP Basic Authentication Bypass
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent st
50RIESGO
abrir ↗Referência✓ VexDay Proof
JBlog 1.0 - 'index.php?id' SQL Injection
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Webquest 2.5 - 'id_actividad' SQL Injection
SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Omnistar Article Manager Software - 'article.php' SQL Injection
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component joom12pic 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla
28RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.0 - 'login.php' SQL Injection
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Chupix CMS 0.2.3 - 'download.php' Remote File Disclosure
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overw
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP 1.0 sondages Module - SQL Injection
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
MW6 Technologies QRCode ActiveX 3.0 - Remote File Overwrite
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Techn
28RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Mod Ktauber.com StylesDemo - Blind SQL Injection
SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to e
23RIESGO
abrir ↗Referência✓ VexDay Proof
Streamline PHP Media Server 1.0-beta4 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to ex
35RIESGO
abrir ↗Referência✓ VexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RIESGO
abrir ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute ar
35RIESGO
abrir ↗Referência✓ VexDay Proof
CMS Made Simple 1.2 - Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir ↗Referência✓ VexDay Proof
Journalness 4.1 - 'last_module' Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir ↗Referência✓ VexDay Proof
Open-Realty 2.4.3 - 'last_module' Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir ↗Referência✓ VexDay Proof
ClanSphere 2007.4 - 'cat_id' SQL Injection
SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_slideshow - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Jo
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke addon Nuke Mobile Entartainment 1.0 - Local File Inclusion
Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
IPSwitch IMail Server 8.0x - Remote Heap Overflow
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ask.com/AskJeeves Toolbar Toolbar 4.0.2.53 - ActiveX Remote Buffer Overflow
Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media
50RIESGO
abrir ↗Referência✓ VexDay Proof
EB Design Pty Ltd - 'EBCRYPT.dll 2.0' Multiple Remote Vulnerabilities
Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
EB Design Pty Ltd - 'EBCRYPT.dll 2.0' Multiple Remote Vulnerabilities
A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗Referência
CVE-2017-6327
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RIESGO
abrir ↗Referência
CVE-2017-6371
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.