Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
cPanel 10.9 - 'dosetmytheme?theme' Cross-Site Scripting
CVE-2006-5535webappsphp23 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DSL-G624T - Information Disclosure
CVE-2006-5536remotehardware23 oct 2006
Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote a
28RIESGO
abrir
Exploit-DBVexDay Proof
SchoolAlumni Portal 2.26 - '/smumdadotcom_ascyb_alumni/mod.php?katalog Module query' Cross-Site Scripting
CVE-2006-5529webappsphp23 oct 2006
Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 10.9 - 'editzonetemplate?template' Cross-Site Scripting
CVE-2006-5535webappsphp23 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
SchoolAlumni Portal 2.26 - 'mod.php?mod' Traversal Local File Inclusion
CVE-2006-5528webappsphp23 oct 2006
Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Zwahlen's Online Shop 5.2.2 - 'Cat' Cross-Site Scripting
CVE-2006-5512webappsphp23 oct 2006
Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
WikiNi 0.4.x - 'Waka.php' Multiple HTML Injection Vulnerabilities
CVE-2006-5516webappsphp23 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
SpeedBerg 1.2beta1 - 'SPEEDBERG_PATH' File Inclusion
CVE-2006-5485webappsphp22 oct 2006
Multiple PHP remote file inclusion vulnerabilities in SpeedBerg 1.2beta1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (1)
CVE-2006-5478remotenovell21 oct 2006
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RIESGO
abrir
Exploit-DBVexDay Proof
Casinosoft Casino Script 3.2 - 'config.php' SQL Injection
CVE-2006-5446webappsphp20 oct 2006
SQL injection vulnerability in lobby/config.php in Casinosoft Casino Script (aka Masvet) 3.2 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Lou Portail 1.4.1 - 'admin_module.php' Remote File Inclusion
CVE-2006-5423webappsphp20 oct 2006
PHP remote file inclusion vulnerability in admin/admin_module.php in Lou Portail 1.4.1, and possibly earlier, allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Asterisk 1.0.12/1.2.12.1 - 'chan_skinny' Remote Heap Overflow (PoC)
CVE-2006-5444dosmultiple19 oct 2006
Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12
45RIESGO
abrir
Exploit-DBVexDay Proof
Power Phlogger 2.0.9 - 'config.inc.php3' File Inclusion
CVE-2002-1885webappsphp19 oct 2006
PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
CVE-2006-5722webappsphp19 oct 2006
Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, all
23RIESGO
abrir
Exploit-DBVexDay Proof
Simple Machines Forum (SMF) 1.0/1.1 - 'index.php' Cross-Site Scripting
CVE-2006-5503webappsphp19 oct 2006
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Ariadne CMS 2.4 - Remote File Inclusion
CVE-2005-1181webappsphp19 oct 2006
NOTE: this issue has been disputed by the vendor. PHP remote code injection vulnerability in loader.php for Ariadne CMS
23RIESGO
abrir
Exploit-DBVexDay Proof
Ipswitch IMail Server 2006 / 8.x - 'RCPT' Remote Stack Overflow
CVE-2006-4379remotewindows19 oct 2006
Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail
35RIESGO
abrir
Exploit-DBVexDay Proof
Free FAQ 1.0 - 'index.php' Remote File Inclusion
CVE-2006-5436webappsphp19 oct 2006
PHP remote file inclusion vulnerability in index.php in FreeFAQ 1.0.e allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
Exploit-DBVexDay Proof
Zorum 3.5 - 'DBProperty.php' Remote File Inclusion
CVE-2006-5431webappsphp19 oct 2006
PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Cerberus Helpdesk 3.2.1 - 'Rpc.php' Unauthorized Access
CVE-2006-5428webappsphp18 oct 2006
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
Kinesis Interactive Cinema System - 'index.asp' SQL Injection
CVE-2006-5450webappsasp18 oct 2006
SQL injection vulnerability in index.asp in Kinesis Interactive Cinema System (KICS) CMS allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
phpList 2.10.2 - 'index.php' Cross-Site Scripting
CVE-2006-5524webappsphp17 oct 2006
Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Clam AntiVirus 0.88.4 - CHM Chunk Name Length Denial of Service (PoC)
CVE-2006-5295dosmultiple17 oct 2006
Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service
28RIESGO
abrir
Exploit-DBVexDay Proof
PHPmybibli 3.0.1 - Multiple Remote File Inclusions
CVE-2006-5402webappsphp17 oct 2006
Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Clam AntiVirus 0.88.4 - 'rebuildpe' Remote Heap Overflow (PoC)
CVE-2006-4182dosmultiple17 oct 2006
Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denia
28RIESGO
abrir
Exploit-DBVexDay Proof
Lodel CMS 0.7.3 - 'Calcul-page.php' Remote File Inclusion
CVE-2006-5422webappsphp17 oct 2006
PHP remote file inclusion vulnerability in calcul-page.php in Lodel (patchlodel) 0.7.3 allows remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
Specimen Image Database - 'client.php' Remote File Inclusion
CVE-2008-7152webappsphp16 oct 2006
Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, a
23RIESGO
abrir
Exploit-DBVexDay Proof
WoltLab Burning Book 1.1.2 - SQL Injection
CVE-2006-5508webappsphp16 oct 2006
Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
WoltLab Burning Book 1.1.2 - SQL Injection
CVE-2006-5509webappsphp16 oct 2006
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
ironwebmail 6.1.1 - Directory Traversal Information Disclosure
CVE-2006-5210webappsphp16 oct 2006
Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files
23RIESGO
abrir
anteriorpágina 570 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.