Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Enthrallweb eHomes 1.0 - Multiple (SQL Injection / Cross-Site Scripting) Vulnerabilities
CVE-2006-6204webappsasp23 dic 2006
Multiple SQL injection vulnerabilities in Enthrallweb eHomes allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
KISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion
CVE-2008-1635webappsphp22 dic 2006
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Portal 9i/10g - Container_Tabs.jsp Cross-Site Scripting
CVE-2006-6703webappsphp22 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Portal 9i and 10g allow remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
KISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion
CVE-2006-6763webappsphp22 dic 2006
Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
Xt-News 0.1 - 'show_news.php?id_news' Cross-Site Scripting
CVE-2006-6746webappsphp22 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Xt-News 0.1 - 'add_comment.php?id_news' Cross-Site Scripting
CVE-2006-6746webappsphp22 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Xt-News 0.1 - 'show_news.php?id_news' SQL Injection
CVE-2006-6747webappsphp22 dic 2006
SQL injection vulnerability in show_news.php in Xt-News 0.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
FTPRush 1.0.610 - Host Field Local Buffer Overflow
CVE-2006-6752dosmultiple22 dic 2006
Buffer overflow in FTPRush 1.0.0.610 might allow attackers to gain privileges via a long Host field. NOTE: The provenan
23RIESGO
abrir
Exploit-DBVexDay Proof
Efkan Forum 1.0 - 'Grup' SQL Injection
CVE-2006-6794webappsasp22 dic 2006
SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
A-Blog 1.0 - Cross-Site Scripting
CVE-2006-6729webappsphp22 dic 2006
Cross-site scripting (XSS) vulnerability in a-blog 1.51 and earlier allows remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
XM Easy Personal FTP Server 5.2.1 - 'USER' Format String Denial of Service
CVE-2006-6751doswindows22 dic 2006
Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (a
23RIESGO
abrir
Exploit-DBVexDay Proof
MKPortal M1.1.1 - 'Urlobox' Cross-Site Request Forgery
CVE-2006-6741webappsphp21 dic 2006
Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messa
23RIESGO
abrir
Exploit-DBVexDay Proof
Mono XSP 1.x/2.0 - Source Code Information Disclosure
CVE-2006-6104remotelinux20 dic 2006
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, whi
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Portal 9.0.2 - Calendar.jsp Multiple HTTP Response Splitting Vulnerabilities
CVE-2006-6697webappsjsp20 dic 2006
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'MessageBox' Memory Corruption Local Denial of Service
CVE-2006-6696doswindows20 dic 2006
Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by callin
23RIESGO
abrir
Exploit-DBVexDay Proof
Typo3 3.7/3.8/4.0 - 'Class.TX_RTEHTMLArea_PI1.php' Multiple Remote Command Execution Vulnerabilities
CVE-2006-6690webappsphp20 dic 2006
rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, a
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Advanced Transfer Manager 1.30 - Source Code Disclosure
CVE-2006-1209webappsphp20 dic 2006
PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web r
23RIESGO
abrir
Exploit-DBVexDay Proof
KDE libkhtml 3.5 < 4.2.0 - Unhandled HTML Parse Exception
CVE-2006-6660doslinux19 dic 2006
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
osTicket 1.2/1.3 Support Cards - 'view.php' Cross-Site Scripting
CVE-2006-6733webappsphp19 dic 2006
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
Intel 2200BG 802.11 - Beacon frame Kernel Memory Corruption
CVE-2006-6651dosmultiple19 dic 2006
Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corrupt
23RIESGO
abrir
Exploit-DBVexDay Proof
Mini Web Shop 2.1.c - 'view.php?Viewcategory.php' Cross-Site Scripting
CVE-2006-6734webappsphp19 dic 2006
Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g - 'extproc' Local/Remote Command Execution
CVE-2004-1364remotemultiple19 dic 2006
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries
28RIESGO
abrir
Exploit-DBVexDay Proof
Burak Yilmaz Download Portal - 'down.asp' SQL Injection
CVE-2006-6671webappsasp19 dic 2006
SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
KDE LibkHTML 4.2 - NodeType Function Denial of Service
CVE-2006-6660doslinux19 dic 2006
The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g - 'utl_file' FileSystem Access
CVE-2006-7141remotelinux19 dic 2006
Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE
23RIESGO
abrir
Exploit-DBVexDay Proof
Knusperleicht Shoutbox 2.6 - 'Shout.php' HTML Injection
CVE-2006-6721webappsphp18 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Outlook - ActiveX Control Remote Internet Explorer Denial of Service
CVE-2006-6659doswindows18 dic 2006
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a
28RIESGO
abrir
Exploit-DBVexDay Proof
Grsecurity Kernel PaX - Local Privilege Escalation
CVE-2007-0257HIGHlocallinux18 dic 2006
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspe
41RIESGO
abrir
Exploit-DBVexDay Proof
RateMe 1.3.2 - 'main.inc.php' Remote File Inclusion
CVE-2006-6648webappsphp18 dic 2006
PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office Outlook Recipient Control - 'ole32.dll' Denial of Service
CVE-2006-6659doswindows18 dic 2006
The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a
28RIESGO
abrir
anteriorpágina 557 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.