Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
EZContents 2.0 - 'gallery_summary.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'review_summary.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'event_list.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'calendar.php?GLOBALS[language_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
CVE-2006-4479webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
IwebNegar 1.1 - 'comments.php' SQL Injection
CVE-2006-4497webappsphp30 ago 2006
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
ZipCentral 4.01 - '.ZIP' File Handling Local Buffer Overflow
CVE-2006-2439localwindows30 ago 2006
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP
23RIESGO
abrir
Exploit-DBVexDay Proof
HLstats 1.34 - 'hlstats.php' Cross-Site Scripting
CVE-2006-4454webappsphp29 ago 2006
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (1)
CVE-2006-3124remotelinux29 ago 2006
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RIESGO
abrir
Exploit-DBVexDay Proof
ModuleBased CMS - Multiple Remote File Inclusions
CVE-2006-4545webappsphp29 ago 2006
PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (2)
CVE-2006-3124remotewindows29 ago 2006
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RIESGO
abrir
Exploit-DBVexDay Proof
Cybozu Products - 'id' Arbitrary File Retrieval
CVE-2006-4490webappscgi28 ago 2006
Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 al
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NetpIsRemote() Remote Overflow (MS06-040) (2)
CVE-2006-3439remotewindows28 ago 2006
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Daxctle.OCX Spline Method Heap Buffer Overflow
CVE-2006-4446remotewindows28 ago 2006
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP
35RIESGO
abrir
Exploit-DBVexDay Proof
Cybuzu Garoon 2.1.0 - Multiple SQL Injections
CVE-2006-4444webappscgi28 ago 2006
Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4441webappsphp27 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'upload_form.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DBVexDay Proof
Alstrasoft Video Share Enterprise 4.x - 'MyajaxPHP.php' Remote File Inclusion
CVE-2006-4443webappsphp26 ago 2006
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'item_main.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DBVexDay Proof
Jetbox CMS 2.1 - 'Search_function.php' Remote File Inclusion
CVE-2006-4422webappsphp26 ago 2006
PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.1.7 - Multiple HTML Injection Vulnerabilities
CVE-2006-4449webappsphp26 ago 2006
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions a
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! / Mambo Component Comprofiler 1.0 - 'class.php' Remote File Inclusion
CVE-2006-4553webappsphp26 ago 2006
PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joom
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (2)
CVE-2006-4927localwindows26 ago 2006
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RIESGO
abrir
Exploit-DBVexDay Proof
Alt-N MDaemon POP3 Server < 9.06 - 'USER' Remote Heap Overflow
CVE-2006-4364remotewindows26 ago 2006
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RIESGO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'admin.cmd.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (1)
CVE-2006-4927localwindows26 ago 2006
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RIESGO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.5 - 'index.php' Remote File Inclusion
CVE-2006-4428CRITICALwebappsphp26 ago 2006
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary P
48RIESGO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'download.cmd.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4425webappsphp24 ago 2006
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DBVexDay Proof
BlackBoard Products 6 - Multiple HTML Injection Vulnerabilities
CVE-2006-4308webappsphp24 ago 2006
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community P
23RIESGO
abrir
anteriorpágina 582 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.