Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
WebChat 0.77 - 'defines.php?WEBCHATPATH' Remote File Inclusion
PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
TeamSpeak 2.0 (Windows Release) - Remote Denial of Service
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Referência✓ VexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RIESGO
abrir ↗Referência✓ VexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir ↗Referência✓ VexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiGCMS 2.0.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RIESGO
abrir ↗Referência✓ VexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RIESGO
abrir ↗Referência✓ VexDay Proof
Durian Web Application Server 3.02 - Denial of Service
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to i
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHProjekt 5.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Citrix Presentation Server Client - 'WFICA.OCX' ActiveX Heap Buffer Overflow
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.23
35RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.1 - 'hash_update_file()' Freed Resource Usage
The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupt
23RIESGO
abrir ↗Referência✓ VexDay Proof
Lama Software 14.12.2007 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir ↗Referência✓ VexDay Proof
IrfanView 3.99 - '.ani' Local Buffer Overflow (1)
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RIESGO
abrir ↗Referência✓ VexDay Proof
Downline Goldmine Builder - SQL Injection
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗Referência✓ VexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RIESGO
abrir ↗Referência✓ VexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RIESGO
abrir ↗Referência✓ VexDay Proof
Megacubo 5.0.7 - 'mega://' Remote 'eval()' Injection
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
SendStudio 2004.14 - 'ROOTDIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.