Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Knox Arkeia Backup Client 5.3.3 Type 77 (OSX) - Overflow (Metasploit)
CVE-2005-0491remoteosx18 feb 2005
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RIESGO
abrir
Exploit-DBVexDay Proof
BibORB 1.3.2 - Add Database 'Description' Cross-Site Scripting
CVE-2005-0251webappsphp17 feb 2005
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
BibORB 1.3.2 Login Module - Multiple SQL Injections
CVE-2005-0252webappsphp17 feb 2005
SQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
paFaq beta4 - 'search.php?search_item' SQL Injection
CVE-2005-0475webappsphp17 feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
3Com FTP Server 2.0 - Remote Overflow
CVE-2005-0277remotewindows17 feb 2005
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RIESGO
abrir
Exploit-DBVexDay Proof
BibORB 1.3.2 - 'bibindex.php?search' Cross-Site Scripting
CVE-2005-0251webappsphp17 feb 2005
Cross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
BibORB 1.3.2 - 'index.php' Traversal Arbitrary File Manipulation
CVE-2005-0253webappsphp17 feb 2005
Directory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
paFaq beta4 - 'question.php' Multiple SQL Injections
CVE-2005-0475webappsphp17 feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
paFaq beta4 - 'comment.php' Multiple SQL Injections
CVE-2005-0475webappsphp17 feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
paFaq beta4 - 'answer.php?offset' SQL Injection
CVE-2005-0475webappsphp17 feb 2005
SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
Typespeed 0.4.1 - Local Format String
CVE-2005-0105locallinux16 feb 2005
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft ASP.NET 1.0/1.1 - Unicode Character Conversion Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-0452webappsasp16 feb 2005
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attacker
28RIESGO
abrir
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - Arbitrary Local PHP File Inclusion
CVE-2005-0411webappsphp15 feb 2005
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to
23RIESGO
abrir
Exploit-DBVexDay Proof
Savant Web Server 3.1 (French Windows)- Remote Buffer Overflow
CVE-2005-0338remotewindows15 feb 2005
Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.
23RIESGO
abrir
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - 'importcc.php' Arbitrary Database Injection
CVE-2005-0409webappsphp15 feb 2005
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (2)
CVE-2005-0429webappsphp15 feb 2005
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled,
23RIESGO
abrir
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - 'importcc.php' CSV File SQL Injection
CVE-2005-0410webappsphp15 feb 2005
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via th
23RIESGO
abrir
Exploit-DBVexDay Proof
CitrusDB 0.3.6 - 'uploadcc.php' Arbitrary Database Injection
CVE-2005-0409webappsphp15 feb 2005
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
AWStats 6.4 - Denial of Service
CVE-2005-0436doscgi14 feb 2005
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of
23RIESGO
abrir
Exploit-DBVexDay Proof
AWStats 6.4 - Denial of Service
CVE-2005-0435doscgi14 feb 2005
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmo
23RIESGO
abrir
Exploit-DBVexDay Proof
Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Traversal Arbitrary File Access
CVE-2005-0442webappsphp14 feb 2005
Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via th
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (1)
CVE-2005-0429webappsphp14 feb 2005
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled,
23RIESGO
abrir
Exploit-DBVexDay Proof
Brooky CubeCart 2.0.1/2.0.4 - 'index.php?language' Cross-Site Scripting
CVE-2005-0443webappsphp14 feb 2005
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-
23RIESGO
abrir
Exploit-DBVexDay Proof
MercuryBoard 1.1.1 - SQL Injection
CVE-2005-0414webappsphp12 feb 2005
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
Quake 3 Engine - Infostring Crash and Shutdown
CVE-2005-0430doswindows12 feb 2005
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown ga
23RIESGO
abrir
Exploit-DBVexDay Proof
CA BrightStor ARCserve Backup - Remote Buffer Overflow (PoC)
CVE-2005-2535doslinux12 feb 2005
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execu
60RIESGO
abrir
Exploit-DBVexDay Proof
CMScore - SQL Injection
CVE-2005-0368webappsphp10 feb 2005
Multiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) E
23RIESGO
abrir
Exploit-DBVexDay Proof
MyPHP Forum 1.0 - SQL Injection
CVE-2005-0413webappsphp10 feb 2005
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir
Exploit-DBVexDay Proof
Armagetron Advanced 0.2.7.0 - Server Crash
CVE-2005-0370doswindows10 feb 2005
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of s
23RIESGO
abrir
Exploit-DBVexDay Proof
Armagetron Advanced 0.2.7.0 - Server Crash
CVE-2005-0369MEDIUMdoswindows10 feb 2005
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of serv
33RIESGO
abrir
anteriorpágina 502 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.