Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
Advanced Poll 2.0.5-dev - Remote Admin Session Generator
admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain admin
23RIESGO
abrir ↗Referência✓ VexDay Proof
Open-Realty 2.4.3 - 'last_module' Remote Code Execution
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir ↗Referência✓ VexDay Proof
ClanSphere 2007.4 - 'cat_id' SQL Injection
SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft DNS Server - Dynamic DNS Update/Change
The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients i
35RIESGO
abrir ↗Referência✓ VexDay Proof
0irc-client 1345 build20060823 - Denial of Service
0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se
23RIESGO
abrir ↗Referência✓ VexDay Proof
IPSwitch IMail Server 8.0x - Remote Heap Overflow
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Wordsmith 1.1b - 'config.inc.php?_path' Remote File Inclusion
PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows
35RIESGO
abrir ↗Referência✓ VexDay Proof
Ask.com/AskJeeves Toolbar Toolbar 4.0.2.53 - ActiveX Remote Buffer Overflow
Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media
50RIESGO
abrir ↗Referência✓ VexDay Proof
EB Design Pty Ltd - 'EBCRYPT.dll 2.0' Multiple Remote Vulnerabilities
Absolute path traversal vulnerability in the EbCrypt.eb_c_PRNGenerator.1 ActiveX control in EBCRYPT.DLL 2.0.0.2087 and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
EB Design Pty Ltd - 'EBCRYPT.dll 2.0' Multiple Remote Vulnerabilities
A certain ActiveX control in EBCRYPT.DLL 2.0 in EB Design ebCrypt allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Novus 1.0 - 'notas.asp?nota_id' SQL Injection
SQL injection vulnerability in notas.asp in Novus 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência✓ VexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
smbftpd 0.96 - SMBDirList-function Remote Format String
Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute a
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP wcms XT 0.0.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execut
35RIESGO
abrir ↗Referência✓ VexDay Proof
Segue CMS 1.8.4 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled,
35RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module mx_glance 2.3.3 - Remote File Inclusion
contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment bec
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion module Expanded Calendar 2.x - SQL Injection
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for P
23RIESGO
abrir ↗Referência✓ VexDay Proof
CyberLink PowerDVD - CreateNewFile Remote Rewrite Denial of Service
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLA
28RIESGO
abrir ↗Referência✓ VexDay Proof
MD-Pro 1.0.76 - SQL Injection
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Solaris 8/9/10 - 'fifofs I_PEEK' Local Kernel Memory Leak
Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the co
23RIESGO
abrir ↗Referência✓ VexDay Proof
PMOS Help Desk 2.4 - Remote Command Execution
form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote at
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ossigeno CMS 2.2a3 - 'footer.php' Remote File Inclusion
PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers t
35RIESGO
abrir ↗Referência✓ VexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Knowledge Base Mod 2.0.2 - 'phpBB' Remote File Inclusion
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier
23RIESGO
abrir ↗Referência✓ VexDay Proof
Cmaps v8.0 - SQL injection
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RIESGO
abrir ↗Referência✓ VexDay Proof
WordPress Plugin Wordspew - SQL Injection
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
VS-News-System 1.2.1 - 'newsordner' Remote File Inclusion
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZContents CMS 2.0.0 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.