Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir
ReferênciaVexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
CVE-2003-1571webappsasp
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting
CVE-2019-14750webappsphp
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w
43RIESGO
abrir
ReferênciaVexDay Proof
Randshop 1.1.1 - 'header.inc.php' Remote File Inclusion
CVE-2006-3375webappsphp
PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.1.0 - Remote File Inclusion
CVE-2006-3528webappsphp
Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component pc_cookbook 0.3 - Remote File Inclusion
CVE-2006-3530webappsphp
PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Jooml
23RIESGO
abrir
ReferênciaVexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
CVE-2006-3572webappsphp
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Winlpd 1.2 Build 1076 - Remote Buffer Overflow
CVE-2006-3670remotewindows
Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a requ
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MiniBB 1.5a - Remote File Inclusion
CVE-2006-3690webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Eskolar CMS 0.9.0.0 - Blind SQL Injection
CVE-2006-3727webappsphp
Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (1)
CVE-2006-3730HIGHremotewindows
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Sitemap 2.0.0 - Remote File Inclusion
CVE-2006-3749webappsphp
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS,
23RIESGO
abrir
ReferênciaVexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
CVE-2006-3754webappsphp
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier a
23RIESGO
abrir
ReferênciaVexDay Proof
Etomite CMS 0.6.1 - 'Username' SQL Injection (mq = off)
CVE-2006-3904webappsphp
SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allow
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Live! 3.2.1 - 'help.php' Remote File Inclusion
CVE-2006-3911webappsphp
PHP remote file inclusion vulnerability in OSI Codes PHP Live! 3.2.1 and earlier allows remote attackers to execute arbi
28RIESGO
abrir
ReferênciaVexDay Proof
WinRAR 3.60 Beta 6 (French) - SFX Path Local Stack Overflow
CVE-2006-3912localwindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RIESGO
abrir
ReferênciaVexDay Proof
Portail PHP 1.7 - 'chemin' Remote File Inclusion
CVE-2006-3922webappsphp
PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Mam-Moodle alpha - Remote File Inclusion
CVE-2006-3951webappsphp
PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_colophon' 1.2 - Remote File Inclusion
CVE-2006-3969webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and
23RIESGO
abrir
ReferênciaVexDay Proof
PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion
CVE-2006-3983webappsphp
PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RIESGO
abrir
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
k_shoutbox 4.4 - Remote File Inclusion
CVE-2006-3989webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
SaveWeb Portal 3.4 - 'SITE_Path' Remote File Inclusion
CVE-2006-4012webappsphp
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections
CVE-2006-4042webappsphp
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
CVE-2006-4045webappsphp
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Open Cubic Player 2.6.0pre6/0.1.10_rc5 - Multiple Local Buffer Overflows
CVE-2006-4046localwindows
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier
28RIESGO
abrir
ReferênciaVexDay Proof
PHP Simple Shop 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4052webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote att
28RIESGO
abrir
ReferênciaVexDay Proof
NEWSolved Lite 1.9.2 - 'abs_path' Remote File Inclusion
CVE-2006-4059webappsphp
Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote a
28RIESGO
abrir
anteriorpágina 184 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.