Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Thwboard Beta 2.8 - 'v_profile.php?user' SQL Injection
CVE-2005-4139webappsphp07 dic 2005
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Thwboard Beta 2.8 - 'calendar.php?year' SQL Injection
CVE-2005-4139webappsphp07 dic 2005
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
NetAuctionHelp 3.0 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4063webappsasp06 dic 2005
Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple Vendor BIOS - Keyboard Buffer Password Persistence (1)
CVE-2005-4176localwindows06 dic 2005
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, whic
23RIESGO
abrir
Exploit-DBVexDay Proof
A-FAQ 1.0 - 'faqDspItem.asp?faqid' SQL Injection
CVE-2005-4064webappsasp06 dic 2005
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple Vendor BIOS - Keyboard Buffer Password Persistence (2)
CVE-2005-4176localunix06 dic 2005
AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, whic
23RIESGO
abrir
Exploit-DBVexDay Proof
PluggedOut Blog 1.9.x - 'index.php' Multiple SQL Injections
CVE-2005-4054webappsphp06 dic 2005
SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
A-FAQ 1.0 - 'faqDsp.asp?catcode' SQL Injection
CVE-2005-4064webappsasp06 dic 2005
Multiple SQL injection vulnerabilities in A-FAQ 1.0 allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
Cars Portal 1.1 - 'index.php' Multiple SQL Injections
CVE-2005-4055webappsphp06 dic 2005
SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
RWAuction Pro 4.0 - 'search.asp' Cross-Site Scripting
CVE-2005-4060webappsasp06 dic 2005
Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Horde IMP 2.2.x/3.2.x/4.0.x - Email Attachments HTML Injection
CVE-2005-4080remotelinux06 dic 2005
Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
IISWorks ASPKnowledgeBase 2.0 - 'KB.asp' Cross-Site Scripting
CVE-2005-4047webappsasp06 dic 2005
Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
DuWare DuPortalPro 3.4.3 - 'Password.asp' Cross-Site Scripting
CVE-2005-4166webappsasp06 dic 2005
Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Relative Real Estate Systems 1.2 - SQL Injection
CVE-2005-4019webappsphp05 dic 2005
SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Blog System 1.2 - 'index.php?cat' SQL Injection
CVE-2005-4049webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eDating Professional 5.0 - 'index.php' Multiple SQL Injections
CVE-2005-4034webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eCommerce Enterprise Edition 2.1 - 'index.php' Multiple SQL Injections
CVE-2005-4035webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eDating Professional 5.0 - 'articles.php?cat' SQL Injection
CVE-2005-4034webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy Search System 1.1 - 'search.cgi' Cross-Site Scripting
CVE-2005-4032webappscgi05 dic 2005
Cross-site scripting (XSS) vulnerability in search.cgi in Easy Search System 1.1 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eDating Professional 5.0 - 'fq.php?cid' SQL Injection
CVE-2005-4034webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eCommerce Enterprise Edition 2.1 - 'view.php' Multiple SQL Injections
CVE-2005-4035webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future Portal Solutions - 'Arhiva.php' Directory Traversal
CVE-2005-4039webappsphp05 dic 2005
Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to re
23RIESGO
abrir
Exploit-DBVexDay Proof
1-Script 1-Search 1.8 - '1search.CGI' Cross-Site Scripting
CVE-2005-4091webappscgi05 dic 2005
Cross-site scripting (XSS) vulnerability in 1search.cgi in 1-Script 1-Search 1.8 allows remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eDating Professional 5.0 - 'gift.php?cid' SQL Injection
CVE-2005-4034webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Hobosworld HobSR - Multiple SQL Injections
CVE-2005-4043webappsphp05 dic 2005
SQL injection vulnerability in view.php in Hobosworld HobSR 1.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Edgewall Software Trac 0.7.1/0.8/0.9 Search Module - SQL Injection
CVE-2005-4065webappsphp05 dic 2005
SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future eCommerce Enterprise Edition 2.1 - 'viewbrands.php?bid' SQL Injection
CVE-2005-4035webappsphp05 dic 2005
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Web4Future Affiliate Manager PRO 4.1 - 'functions.php' SQL Injection
CVE-2005-4037webappsphp05 dic 2005
SQL injection vulnerability in functions.php in Web4Future Affiliate Manager PRO 4.1 and earlier allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
SAMEDIA LandShop 0.6.3 - 'ls.php' Multiple SQL Injections
CVE-2005-4018webappsphp05 dic 2005
SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
DoceboLms 2.0.4 - 'connector.php' Arbitrary File Upload
CVE-2005-4095webappsphp04 dic 2005
Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers
23RIESGO
abrir
anteriorpágina 458 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.