Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
bitweaver 1.x - '/newsletters/edition.php?tk' SQL Injection
CVE-2006-6923webappsphp09 nov 2006
SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
LandShop 0.6.3 - 'ls.php' Multiple SQL Injections
CVE-2006-5914webappsphp09 nov 2006
SQL injection vulnerability in ls.php in SAMEDIA LandShop allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
LandShop 0.6.3 - 'ls.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-5915webappsphp09 nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in ls.php in SAMEDIA LandShop allow remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeWebShop 2.1/2.2 - 'index.php?page' Traversal Arbitrary File Access
CVE-2006-5846webappsphp08 nov 2006
Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and incl
28RIESGO
abrir
Exploit-DBVexDay Proof
FreeWebShop 2.1/2.2 - 'index.php?cat' Cross-Site Scripting
CVE-2006-5847webappsphp08 nov 2006
Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Immediacy .NET CMS 5.2 - 'Logon.aspx' Cross-Site Scripting
CVE-2006-5853webappsasp08 nov 2006
Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
NewP News Publishing System 1.0 - 'Class.Database.php' Remote File Inclusion
CVE-2006-5838webappsphp07 nov 2006
PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_g
23RIESGO
abrir
Exploit-DBVexDay Proof
WarFTPd 1.82.00-RC11 - Remote Denial of Service
CVE-2006-5789doswindows07 nov 2006
War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number
23RIESGO
abrir
Exploit-DBVexDay Proof
IPManager 2.3 - 'index.php' Cross-Site Scripting
CVE-2006-5924webappsphp07 nov 2006
Cross-site scripting (XSS) vulnerability in index.php in Efficient IP iPmanager (IPm) 2.3 allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Kayako SupportSuite 3.0.32 - 'index.php' Cross-Site Scripting
CVE-2006-5825webappsphp07 nov 2006
Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_news.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_dpage.php' Cross-Site Scripting
CVE-2006-5830webappsphp06 nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_users_online.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
America Online ICQ 5.1 - ActiveX Control Remote Code Execution
CVE-2006-5650remotewindows06 nov 2006
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute
50RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_links_search.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_forum_view.php' Cross-Site Scripting
CVE-2006-5830webappsphp06 nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_links.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'load_page' Remote File Inclusion
CVE-2006-5831webappsphp06 nov 2006
PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_show_page_help.php' Full Path Disclosure
CVE-2006-5832webappsphp06 nov 2006
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server v
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_newsletter.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_show_ec_products.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_login.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_show_ec_products.php' Full Path Disclosure
CVE-2006-5832webappsphp06 nov 2006
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server v
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_show_ec_products.php' Cross-Site Scripting
CVE-2006-5830webappsphp06 nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_edit_user.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_codice_fiscale.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Article Script 1.6.3 - 'rss.php' SQL Injection
CVE-2006-5765webappsphp06 nov 2006
SQL injection vulnerability in rss.php in Article Script 1.6.3 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_dpage.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_users_online.php' Cross-Site Scripting
CVE-2006-5830webappsphp06 nov 2006
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
AIOCP 1.3.x - 'cp_contact_us.php' SQL Injection
CVE-2006-5829webappsphp06 nov 2006
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to
23RIESGO
abrir
anteriorpágina 388 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.