Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
5629 exploits
Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser
50RIESGO
abrir ↗Referência✓ VexDay Proof
Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a craft
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiteNews 0.1 - Insecure Cookie Handling
LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mosaic Commerce - 'cid' SQL Injection
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
Jamroom 4.0.2 - 't' Local File Inclusion
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions
23RIESGO
abrir ↗Referência✓ VexDay Proof
CafeEngine - Multiple SQL Injections
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dart Communications PowerTCP FTP module - Remote Buffer Overflow
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir ↗Referência✓ VexDay Proof
PowerTCP FTP Module - Multiple Techniques (SEH HeapSpray)
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir ↗Referência✓ VexDay Proof
ASX to MP3 Converter - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗Referência✓ VexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir ↗Referência✓ VexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
MODx CMS 0.9.2.1 - 'FCKeditor' Remote File Inclusion
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS
23RIESGO
abrir ↗Referência✓ VexDay Proof
pPIM 1.0 - Arbitrary File Delete / Cross-Site Scripting
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
ClaSS 0.8.60 - 'export.php' Local File Inclusion
Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Durian Web Application Server 3.02 - Remote Buffer Overflow
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ax Developer CMS 0.1.1 - 'index.php?module' Local File Inclusion
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and
23RIESGO
abrir ↗Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3)
23RIESGO
abrir ↗Referência✓ VexDay Proof
Aardvark Topsites PHP 4.2.2 - 'path' Remote File Inclusion
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_gl
23RIESGO
abrir ↗Referência✓ VexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
RPG.Board 0.0.8Beta2 - 'showtopic' SQL Injection
SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (1)
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir ↗Referência✓ VexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.