Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Local Privilege Escalation (MS06-049)
CVE-2006-3444localwindows21 sep 2006
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to
28RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updatemail' Servlet Arbitrary Mail Message Manipulation
CVE-2006-4952webappsjsp20 sep 2006
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Dr.Web AntiVirus 4.33 - LHA long Directory name Local Overflow
CVE-2006-4438locallinux20 sep 2006
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote att
28RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'downloadfile' Servlet Traversal Arbitrary File Access
CVE-2006-4955webappsjsp20 sep 2006
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updateuser?in_name' Servlet Cross-Site Scripting
CVE-2006-4956webappsjsp20 sep 2006
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updateuser?in_id' Servlet Arbitrary User Information Modification
CVE-2006-4954webappsjsp20 sep 2006
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'addrlist' Servlet Multiple SQL Injections
CVE-2006-4953webappsjsp20 sep 2006
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'maillist' Servlet Multiple SQL Injections
CVE-2006-4953webappsjsp20 sep 2006
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
ESyndiCat 1.5 - 'search.php' Cross-Site Scripting
CVE-2006-4923webappsphp19 sep 2006
Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - 'common.php?root_path' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - '/admin/index.php?root_path' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - '/admin/config.php?root_path' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
RedBLoG 0.5 - 'imgen.php?Root' Remote File Inclusion
CVE-2006-5021CRITICALwebappsphp19 sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir
Exploit-DBVexDay Proof
Innovate Portal 2.0 - 'index.php' Cross-Site Scripting
CVE-2006-4915webappsphp19 sep 2006
Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NixieAffiliate 1.9 - 'lostpassword.php' Cross-Site Scripting
CVE-2006-4894webappsphp18 sep 2006
Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
EShoppingPro 1.0 - 'Search_Run.asp' SQL Injection
CVE-2006-4871webappsasp18 sep 2006
SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
ECardPro 2.0 - 'search.asp' SQL Injection
CVE-2006-4872webappsasp18 sep 2006
SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
PT News 1.7.8 - 'search.php' Cross-Site Scripting
CVE-2006-4917webappsphp18 sep 2006
Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
DotNetNuke 4.0 - HTML Injection
CVE-2006-4973webappsasp17 sep 2006
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5
23RIESGO
abrir
Exploit-DBVexDay Proof
Charon Cart 3.0 - 'Review.asp' SQL Injection
CVE-2006-4882webappsasp17 sep 2006
SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (2)
CVE-2006-4612webappsphp17 sep 2006
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4865webappsphp16 sep 2006
Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/inst
23RIESGO
abrir
Exploit-DBVexDay Proof
Hitweb 3.0 - 'REP_CLASS' Multiple Remote File Inclusions
CVE-2006-4848webappsphp16 sep 2006
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-post Web Forum 0.x.1.0 - 'profile.php' Multiple SQL Injections
CVE-2006-4877webappsphp16 sep 2006
Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite a
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-post Web Forum 0.x.1.0 - 'pm.php?replyuser' Cross-Site Scripting
CVE-2006-4881webappsphp16 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.4/1.1.5 - '/modules/blocks.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-4874webappsphp15 sep 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.4/1.1.5 - modules/register Multiple SQL Injections
CVE-2006-4876webappsphp15 sep 2006
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.4/1.1.5 - 'galleryuploadfunction.php' Arbitrary File Upload
CVE-2006-4875webappsphp15 sep 2006
Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to up
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec (Multiple Products) - 'SymEvent' Driver Local Denial of Service
CVE-2006-4855doswindows15 sep 2006
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
CVE-2006-4921webappsphp15 sep 2006
PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
anteriorpágina 577 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.