Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.925exploits catalogados
37.570CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Vortex Portal 2.0 - 'index.php?act' Remote File Inclusion
CVE-2005-0879webappsphp23 mar 2005
PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Interspire ArticleLive 2005 - NewComment Cross-Site Scripting
CVE-2005-0881webappsphp23 mar 2005
Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPSysInfo 2.0/2.3 - 'system_footer.php' Cross-Site Scripting
CVE-2005-0870webappsphp23 mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
DigitalHive 2.0 - 'msg.php' Cross-Site Scripting
CVE-2005-0883webappsphp23 mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPSysInfo 2.0/2.3 - 'sensor_program' Cross-Site Scripting
CVE-2005-0870webappsphp23 mar 2005
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Vortex Portal 2.0 - 'content.php?act' Remote File Inclusion
CVE-2005-0879webappsphp23 mar 2005
PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.3.8 - 'CF_CHARSET_PATH' Local Buffer Overflow / Local Privilege Escalation
CVE-2005-0716localosx22 mar 2005
Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Local Denial of Service
CVE-2005-0852doswindows22 mar 2005
Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw I
23RIESGO
abrir
Exploit-DBVexDay Proof
Kayako ESupport 2.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0842webappsphp22 mar 2005
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Phorum 3.x/5.0.x - HTTP Response Splitting
CVE-2005-0843webappsphp22 mar 2005
CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - 'uselib()' Local Privilege Escalation (3)
CVE-2004-1235locallinux22 mar 2005
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.4
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.3.x - Multiple Vulnerabilities
CVE-2005-0713localosx21 mar 2005
The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.12 - Change User Rights Authentication Bypass
CVE-2005-0614webappsphp21 mar 2005
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid va
23RIESGO
abrir
Exploit-DBVexDay Proof
BetaParticle blog 2.0/3.0 - 'myFiles.asp' File Manipulation
CVE-2005-0854webappsasp21 mar 2005
betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload
23RIESGO
abrir
Exploit-DBVexDay Proof
BetaParticle blog 2.0/3.0 - dbBlogMX.mdb Direct Request Database Disclosure
CVE-2005-0853webappsasp21 mar 2005
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive in
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyFamily 1.4.0 - Authentication Bypass
CVE-2005-0841webappsphp21 mar 2005
SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passth
23RIESGO
abrir
Exploit-DBVexDay Proof
BetaParticle blog 2.0/3.0 - 'upload.asp' Arbitrary File Upload
CVE-2005-0854webappsasp21 mar 2005
betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload
23RIESGO
abrir
Exploit-DBVexDay Proof
TRG News 3.0 Script - Remote File Inclusion
CVE-2005-0860webappsphp21 mar 2005
PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via
23RIESGO
abrir
Exploit-DBVexDay Proof
CzarNews 1.13/1.14 - 'headlines.php' Remote File Inclusion
CVE-2005-0859webappsphp21 mar 2005
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the
28RIESGO
abrir
Exploit-DBVexDay Proof
FUN labs Game Engine - Multiple Remote Denial of Service Vulnerabilities
CVE-2005-0848doswindows20 mar 2005
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt,
23RIESGO
abrir
Exploit-DBVexDay Proof
CoolForum 0.5/0.7/0.8 - 'avatar.php?img' Cross-Site Scripting
CVE-2005-0857webappsphp19 mar 2005
Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
CoolForum 0.5/0.7/0.8 - 'register.php?login' SQL Injection
CVE-2005-0858webappsphp19 mar 2005
Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Fusion 4/5 - 'Setuser.php' HTML Injection
CVE-2005-0829webappsphp19 mar 2005
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
Subdreamer 1.0 - SQL Injection
CVE-2005-0805webappsphp18 mar 2005
SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
RunCMS 1.1 - Database Configuration Information Disclosure
CVE-2005-0828webappsphp18 mar 2005
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xo
23RIESGO
abrir
Exploit-DBVexDay Proof
Icecast 2.x - XSL Parser Multiple Vulnerabilities
CVE-2005-0838remotemultiple18 mar 2005
Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possib
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPOpenChat 3.0.1 - Multiple HTML Injection Vulnerabilities
CVE-2005-0863webappsphp18 mar 2005
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or H
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - Multiple ISO9660 Filesystem Handling Vulnerabilities
CVE-2005-0815doslinux17 mar 2005
Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cau
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/2003 - Graphical Device Interface Library Denial of Service
CVE-2005-0803doswindows17 mar 2005
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (
35RIESGO
abrir
Exploit-DBVexDay Proof
MailEnable 1.8 - Remote Format String Denial of Service
CVE-2005-0804doswindows17 mar 2005
Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) v
23RIESGO
abrir
anteriorpágina 498 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.