Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Apache 1.3.35/2.0.58/2.2.2 - Arbitrary HTTP Request Headers Security
CVE-2006-3918remotelinux24 ago 2006
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before
45RIESGO
abrir
Exploit-DBVexDay Proof
Solaris 8/9 - '/usr/ucb/ps' Local Information Leak
CVE-1999-1587localsolaris22 ago 2006
/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environmen
23RIESGO
abrir
Exploit-DBVexDay Proof
RedBlog 0.5 - 'index.php' Remote File Inclusion
CVE-2006-4366webappsphp22 ago 2006
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP cod
23RIESGO
abrir
Exploit-DBVexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
CVE-2009-3962doshardware22 ago 2006
The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.
23RIESGO
abrir
Exploit-DBVexDay Proof
Solaris 10 sysinfo(2) - Local Kernel Memory Disclosure (2)
CVE-2006-3824localsolaris22 ago 2006
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo sys
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - Multiple COM Object Instantiation Code Execution Vulnerabilities
CVE-2006-4495doswindows21 ago 2006
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execut
28RIESGO
abrir
Exploit-DBVexDay Proof
DieselScripts DieselPay - 'index.php' Cross-Site Scripting
CVE-2006-4358webappsphp21 ago 2006
Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
ToendaCMS 0.x/1.0.x - 'TCMS_Administer' Remote File Inclusion
CVE-2006-4349webappsphp21 ago 2006
PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
Exploit-DBVexDay Proof
PHProjekt Content Management Module 0.6.1 - Multiple Remote File Inclusions
CVE-2006-4609webappsphp21 ago 2006
Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache < 1.3.37/2.0.59/2.2.3 mod_rewrite - Remote Overflow
CVE-2006-3747remotemultiple21 ago 2006
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 10.x - 'showfile.html?File' Cross-Site Scripting
CVE-2006-4293webappsphp21 ago 2006
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 10.x - 'editit.html?File' Cross-Site Scripting
CVE-2006-4293webappsphp21 ago 2006
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Multiple COM Object Color Property Denial of Service Vulnerabilities
CVE-2006-4301doswindows21 ago 2006
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RIESGO
abrir
Exploit-DBVexDay Proof
DieselScripts Diesel Paid Mail - 'Getad.php' Cross-Site Scripting
CVE-2006-4362webappsphp21 ago 2006
Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
DieselScripts Smart Traffic - 'index.php' Remote File Inclusion
CVE-2006-4357webappsphp21 ago 2006
PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Component EstateAgent 1.0.2 - MosConfig_absolute_path Remote File Inclusion
CVE-2006-4322webappsphp21 ago 2006
PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, whe
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy File Sharing FTP Server 2.0 - 'PASS' Remote
CVE-2006-3952remotewindows21 ago 2006
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 10.x - 'dohtaccess.html?dir' Cross-Site Scripting
CVE-2006-4293webappsphp21 ago 2006
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script o
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CanonicalizePathName() Remote (MS06-040)
CVE-2006-3439remotewindows19 ago 2006
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RIESGO
abrir
Exploit-DBVexDay Proof
XennoBB 1.0.x/2.2 - Icon_Topic SQL Injection
CVE-2006-4279webappsphp19 ago 2006
SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
CVE-2006-4277webappsphp19 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Sonium Enterprise Adressbook 0.2 - 'folder' Include
CVE-2006-4311webappsphp18 ago 2006
PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Artlinks 1.0b4 - Remote File Inclusion
CVE-2006-3949webappsphp18 ago 2006
PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell Identity Manager - Arbitrary Command Execution
CVE-2006-4310localnovell18 ago 2006
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when at
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU BinUtils 2.1x - GAS Buffer Overflow
CVE-2005-4807remotelinux17 ago 2006
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundati
28RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 4/5 - SUID Routine Miscalculation Arbitrary DML Statement Execution
CVE-2006-4227remotelinux17 ago 2006
MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's
28RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Mosets Tree 1.0 - Remote File Inclusion
CVE-2006-3990webappsphp17 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree compo
28RIESGO
abrir
Exploit-DBVexDay Proof
CubeCart 3.0.11 - 'oid' Blind SQL Injection
CVE-2006-4267webappsphp17 ago 2006
Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - 'TSUserEX.dll' ActiveX Control Memory Corruption
CVE-2006-4219remotewindows17 ago 2006
The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibl
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP 4.4.3/5.1.4 - 'sscanf' Local Buffer Overflow
CVE-2006-4020locallinux16 ago 2006
scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code vi
23RIESGO
abrir
anteriorpágina 583 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.