Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
GeoVision LiveX 8200 - ActiveX 'LIVEX_~1.OCX' File Corruption
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control
23RIESGO
abrir ↗Referência✓ VexDay Proof
pHNews Alpha 1 - 'genbackup.php' Database Disclosure
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Trawler Web CMS 1.8.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
ID Automation Linear Barcode - ActiveX Denial of Service
Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Musoo 0.21 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RIESGO
abrir ↗Referência✓ VexDay Proof
NEPT Image Uploader 1.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader
23RIESGO
abrir ↗Referência✓ VexDay Proof
PA168 Chipset IP Phones - Weak Session Management
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RIESGO
abrir ↗Referência✓ VexDay Proof
Remote Display Dev kit 1.2.1.0 - 'RControl.dll' Denial of Service
Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of
23RIESGO
abrir ↗Referência✓ VexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inj
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean FTP Server 1.00 - Denial of Service
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RIESGO
abrir ↗Referência✓ VexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier fo
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Spreadsheet 0.6 - SQL Injection
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
RSS-aggregator - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpCC 4.2 Beta - 'base_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
75RIESGO
abrir ↗Referência✓ VexDay Proof
MyPHPcommander 2.0 - 'package.php' Remote File Inclusion
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir ↗Referência✓ VexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
Versado CMS 1.07 - 'ajax_listado.php?urlModulo' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
ACG-ScriptShop - 'cid' SQL Injection
SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple iTunes 8.1.1 - 'ITMS' Multiple Protocol Handler Buffer Overflow (Metasploit)
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir ↗Referência✓ VexDay Proof
Apple iTunes 8.1.1.10 (Windows) - 'itms/itcp' Remote Buffer Overflow
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir ↗Referência✓ VexDay Proof
addalink 4 Beta - Write Approved Links
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
KnowledgeBuilder 2.2 - 'visEdit_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.