Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
FreeBSD 5.4/6.0 - 'ptrace PT_LWPINFO' Local Denial of Service
CVE-2006-4516dosbsd12 oct 2006
Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and k
23RIESGO
abrir
Exploit-DBVexDay Proof
CommunityPortals 1.0 - 'bug.php' Remote File Inclusion
CVE-2006-7146webappsphp11 oct 2006
PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier all
23RIESGO
abrir
Exploit-DBVexDay Proof
CommunityPortals 1.0 - 'import-archive.php' File Inclusion
CVE-2006-5739webappsphp11 oct 2006
PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31
23RIESGO
abrir
Exploit-DBVexDay Proof
Hastymail 1.x - IMAP SMTP Command Injection
CVE-2006-5262webappsphp10 oct 2006
CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated
23RIESGO
abrir
Exploit-DBVexDay Proof
BlueShoes Framework 4.6 - 'GoogleSearch.php' Remote File Inclusion
CVE-2006-5250webappsphp10 oct 2006
PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Tagit2b - 'DelTagUser.php' Remote File Inclusion
CVE-2006-5249webappsphp10 oct 2006
PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
EXPBlog 0.3.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-5239webappsphp09 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
phpWebSite 0.10.2 - 'PHPWS_SOURCE_DIR' Multiple Remote File Inclusions
CVE-2006-5234webappsphp09 oct 2006
Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenDock Easy Doc 1.4 - 'doc_directory' File Inclusion
CVE-2006-5244webappsphp09 oct 2006
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabl
23RIESGO
abrir
Exploit-DBVexDay Proof
ISearch 2.16 - 'ISEARCH_PATH' Remote File Inclusion
CVE-2006-5232webappsphp09 oct 2006
Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DBVexDay Proof
Zabbix 1.1.2 - Multiple Remote Code Execution Vulnerabilities
CVE-2006-6692doslinux09 oct 2006
Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (applicati
23RIESGO
abrir
Exploit-DBVexDay Proof
Deep CMS 2.0 - 'index.php' Remote File Inclusion
CVE-2006-5251webappsphp09 oct 2006
PHP remote file inclusion vulnerability in index.php in Deep CMS 2.0a allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenDock Easy Doc 1.4 - 'doc_directory' File Inclusion
CVE-2006-5243webappsphp09 oct 2006
Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enable
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPPC 1.03 RC1 - '/lib/functions.inc.php' Remote File Inclusion
CVE-2006-7135webappsphp08 oct 2006
PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Moodle Blog 1.18.2.2/1.6.2 Module - SQL Injection
CVE-2006-5219webappsphp08 oct 2006
SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
AckerTodo 4.2 - 'login.php' Multiple SQL Injections
CVE-2006-5228webappsphp06 oct 2006
Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 an
23RIESGO
abrir
Exploit-DBVexDay Proof
eXtremail 1.x/2.1 - Remote Format String (3)
CVE-2001-1078remotelinux06 oct 2006
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RIESGO
abrir
Exploit-DBVexDay Proof
Emek Portal 2.1 - 'Uyegiris.asp' SQL Injection
CVE-2006-5217webappsasp06 oct 2006
SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
Civica - 'Display.asp' SQL Injection
CVE-2006-7231webappsasp05 oct 2006
SQL injection vulnerability in display.asp in Civica Software Civica allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 3 < 5 - ZendEngine ECalloc Integer Overflow
CVE-2006-4812remotephp05 oct 2006
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argume
28RIESGO
abrir
Exploit-DBVexDay Proof
WikyBlog 1.2.x - 'index.php' Remote File Inclusion
CVE-2006-5193webappsphp05 oct 2006
PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Computer Associates Products Message Engine RPC Server - Multiple Buffer Overflow Vulnerabilities (1)
CVE-2006-5143remotewindows05 oct 2006
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve B
60RIESGO
abrir
Exploit-DBVexDay Proof
Computer Associates Products Message Engine RPC Server - Multiple Buffer Overflow Vulnerabilities (2)
CVE-2006-5143remotewindows05 oct 2006
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve B
60RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/orders_status.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
JAF CMS 4.0 RC1 - Multiple Remote File Inclusions
CVE-2008-1609webappsphp04 oct 2006
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/newsletters.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/stats_products_purchased.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/countries.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
JAF CMS 4.0 RC1 - Multiple Remote File Inclusions
CVE-2006-7127webappsphp04 oct 2006
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB Static Topics 1.0 - 'phpbb_root_path' File Inclusion
CVE-2006-5191webappsphp04 oct 2006
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for
23RIESGO
abrir
anteriorpágina 393 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.