Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.097exploits catalogados
36.319CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.936GitHub PoC 15.007VulnCheck XDB 8843Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir ↗Referência✓ VexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RIESGO
abrir ↗Referência✓ VexDay Proof
Versado CMS 1.07 - 'ajax_listado.php?urlModulo' Remote File Inclusion
PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpAddressBook 2.11 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3
23RIESGO
abrir ↗Referência✓ VexDay Proof
Interact 2.4.1 - 'help.php' Local File Inclusion
Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPPeanuts 1.3 Beta - 'Inspect.php' Remote File Inclusion
PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpRealty 0.3 - 'INC' Remote File Inclusion
PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other ver
23RIESGO
abrir ↗Referência✓ VexDay Proof
MDForum 2.0.1 - 'PNSVlang' Remote Code Execution
Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_
23RIESGO
abrir ↗Referência✓ VexDay Proof
Natterchat 1.1 - Remote Authentication Bypass
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete room
23RIESGO
abrir ↗Referência✓ VexDay Proof
pragmaMX Module Landkarten 2.1 (Windows) - Local File Inclusion
Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to inclu
23RIESGO
abrir ↗Referência✓ VexDay Proof
ACG-ScriptShop - 'cid' SQL Injection
SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple iTunes 8.1.1 - 'ITMS' Multiple Protocol Handler Buffer Overflow (Metasploit)
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir ↗Referência✓ VexDay Proof
Apple iTunes 8.1.1.10 (Windows) - 'itms/itcp' Remote Buffer Overflow
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! 1.5.x - 'Token' Remote Admin Change Password
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
RhinoSoft Serv-U FTP Server 7.4.0.1 - 'SMNT' (Authenticated) Denial of Service
The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service
23RIESGO
abrir ↗Referência✓ VexDay Proof
Glossword 1.8.1 - 'custom_vars.php' Remote File Inclusion
PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
CounterPath X-Lite 3.x - SIP phone Remote Denial of Service
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash)
23RIESGO
abrir ↗Referência✓ VexDay Proof
addalink 4 Beta - Write Approved Links
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field
23RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
KnowledgeBuilder 2.2 - 'visEdit_root' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2
23RIESGO
abrir ↗Referência✓ VexDay Proof
IrfanView 4.00 - '.iff' Local Buffer Overflow
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RIESGO
abrir ↗Referência✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir ↗Referência✓ VexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.