Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/zones.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
JAF CMS 4.0 RC1 - Multiple Remote File Inclusions
CVE-2006-7127webappsphp04 oct 2006
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB Admin Topic Action Logging Mod 0.94b - Remote File Inclusion
CVE-2006-5209webappsphp04 oct 2006
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 a
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/banner_manager.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/specials.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/reviews.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/tax_classes.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB Static Topics 1.0 - 'phpbb_root_path' File Inclusion
CVE-2006-5191webappsphp04 oct 2006
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/currencies.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/products_expected.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/stats_products_viewed.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.2 - '/admin/stats_products_purchased.php?page' Cross-Site Scripting
CVE-2006-5190webappsphp04 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPGreetz 0.99 - 'footer.php' Remote File Inclusion
CVE-2006-5192webappsphp04 oct 2006
PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
JAF CMS 4.0 RC1 - Multiple Remote File Inclusions
CVE-2008-1609webappsphp04 oct 2006
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
JAF CMS 4.0 RC1 - 'forum.php' Remote File Inclusion
CVE-2008-1609webappsphp03 oct 2006
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
Motorola SB4200 - Remote Denial of Service
CVE-2006-5196doshardware03 oct 2006
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (de
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Web Scripts Easy Banner - 'functions.php' Remote File Inclusion
CVE-2006-5166webappsphp02 oct 2006
PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Digishop 4.0 - 'cart.php' Cross-Site Scripting
CVE-2006-5164webappsphp02 oct 2006
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
DeluxeBB 1.09 - 'Sig.php' Remote File Inclusion
CVE-2006-5154webappsphp02 oct 2006
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
McAfee ePo 3.5.0 / ProtectionPilot 1.1.0 - Source Remote (Metasploit)
CVE-2006-5156remotewindows01 oct 2006
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 10.8.x - cpwrap via MySQLAdmin Privilege Escalation
CVE-2006-5014HIGHlocallinux01 oct 2006
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspe
41RIESGO
abrir
Exploit-DBVexDay Proof
Yblog - 'uss.php' Cross-Site Scripting
CVE-2006-5146webappsphp30 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HT
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyWebmin 1.0 - 'target' Remote File Inclusion
CVE-2006-5124webappsphp30 sep 2006
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyWebmin 1.0 - 'target' Remote File Inclusion
CVE-2006-5125webappsphp30 sep 2006
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.7 - Mach Exception Handling Local (10.3.x)
CVE-2006-4392localosx30 sep 2006
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, al
23RIESGO
abrir
Exploit-DBVexDay Proof
Yblog - 'tem.php' Cross-Site Scripting
CVE-2006-5146webappsphp30 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HT
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.7 - Mach Exception Handling Privilege Escalation
CVE-2006-4392localosx30 sep 2006
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, al
23RIESGO
abrir
Exploit-DBVexDay Proof
Yblog - 'funk.php' Cross-Site Scripting
CVE-2006-5146webappsphp30 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HT
23RIESGO
abrir
Exploit-DBVexDay Proof
Geotarget - 'script.php' Remote File Inclusion
CVE-2006-5141webappsphp29 sep 2006
PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - WebViewFolderIcon setSlice() (2)
CVE-2006-3730HIGHremotewindows29 sep 2006
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RIESGO
abrir
anteriorpágina 573 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.