Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
ACGV News 0.9.1 - 'header.php' Remote File Inclusion
CVE-2006-4637webappsphp07 sep 2006
Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4649webappsphp06 sep 2006
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Uni-vert PHPLeague 0.82 - 'Joueurs.php' SQL Injection
CVE-2006-4643webappsphp06 sep 2006
SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
SoftBB 0.1 - 'Page' Cross-Site Scripting
CVE-2006-4593webappsphp05 sep 2006
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
AnnonceV News Script 1.1 - 'page' Remote File Inclusion
CVE-2006-4622webappsphp05 sep 2006
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
DSocks 1.3 - 'Name' Buffer Overflow (PoC)
CVE-2006-4611dosmultiple05 sep 2006
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (1)
CVE-2006-4612webappsasp05 sep 2006
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy Address Book Web Server 1.2 - Remote Format String
CVE-2006-4654remotewindows04 sep 2006
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (cr
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke MyHeadlines 4.3.1 Module - Cross-Site Scripting
CVE-2006-4563webappsphp04 sep 2006
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Proxima 6.0 - 'BB_Smilies.php' Local File Inclusion
CVE-2006-4631webappsphp04 sep 2006
Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote auth
23RIESGO
abrir
Exploit-DBVexDay Proof
Yappa-ng 2.3.1 - 'admin_modules' Remote File Inclusion
CVE-2005-1312webappsphp03 sep 2006
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
Exploit-DBVexDay Proof
Annuaire 1Two 2.2 - SQL Injection
CVE-2006-4601webappsphp02 sep 2006
SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
Autentificator 2.01 - 'Aut_Verifica.Inc.php' SQL Injection
CVE-2006-4599webappsphp02 sep 2006
SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
VBZoom 1.11 - 'profile.php' Cross-Site Scripting
CVE-2006-4634webappsphp01 sep 2006
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script o
23RIESGO
abrir
Exploit-DBVexDay Proof
Internet Security Systems 3.6 BlackICE - Local Denial of Service
CVE-2006-4541doswindows01 sep 2006
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a den
23RIESGO
abrir
Exploit-DBVexDay Proof
PowerZip 7.06.38950 - 'Filename Handling' Local Buffer Overflow
CVE-2006-4359localwindows01 sep 2006
Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBace Light - 'login_check.php' Remote File
CVE-2006-4596webappsphp01 sep 2006
PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
CVE-2006-4559webappsphp31 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
VisualShapers EZContents 2.0.3 - 'Headeruserdata.php' SQL Injection
CVE-2006-4478webappsphp30 ago 2006
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
HLstats 1.34 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-4543webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'search.php?GLOBALS[language_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'showguestbook.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Digiappz Freekot 1.01 - ASP SQL Injection
CVE-2006-4524webappsasp30 ago 2006
Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
ZipCentral 4.01 - '.ZIP' File Handling Local Buffer Overflow
CVE-2006-2439localwindows30 ago 2006
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP
23RIESGO
abrir
Exploit-DBVexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
CVE-2006-4479webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'shownews.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'showlinks.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
IwebNegar 1.1 - 'comments.php' SQL Injection
CVE-2006-4497webappsphp30 ago 2006
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0 - 'gallery_summary.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'review_summary.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
anteriorpágina 581 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.