Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
PHP-Nuke - 'INP modules.php' Cross-Site Scripting
CVE-2006-3948webappsphp28 jul 2006
Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Plugin JD-WordPress 2.0-1.0 RC2 - 'wp-comments-post.php' Remote File Inclusion
CVE-2006-4992webappsphp28 jul 2006
Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - NDFXArtEffects Stack Overflow
CVE-2006-3943doswindows27 jul 2006
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/2003 - Explorer Drag and Drop Remote Code Execution
CVE-2006-3281remotewindows27 jul 2006
Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attacke
35RIESGO
abrir
Exploit-DBVexDay Proof
eIQnetworks License Manager - Remote Buffer Overflow (multi) (1)
CVE-2006-3838remotewindows27 jul 2006
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RIESGO
abrir
Exploit-DB
ZYXEL Prestige 660H-61 ADSL Router - Cross-Site Scripting
CVE-2006-3929webappshardware27 jul 2006
Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router runnin
23RIESGO
abrir
Exploit-DBVexDay Proof
Bosdates 3.x/4.0 - 'Payment.php' Remote File Inclusion
CVE-2006-3957webappsphp27 jul 2006
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary P
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux-HA Heartbeat 1.2.3/2.0.x - Insecure Default Permissions on Shared Memory
CVE-2006-3815locallinux27 jul 2006
heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local u
23RIESGO
abrir
Exploit-DBVexDay Proof
MidiRecord2 MidiRecord.CC - Local Buffer Overflow
CVE-2006-3931locallinux27 jul 2006
Buffer overflow in the daemon function in midirecord.cc in Tuomas Airaksinen Midirecord 2.0 allows local users to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
GeoClassifieds Enterprise 2.0.5.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-7072webappsphp27 jul 2006
Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
wwwThreads - 'calendar.php' Cross-Site Scripting
CVE-2006-3909webappsphp26 jul 2006
Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBB-Auction 1.x - 'auction_room.php?ar' SQL Injection
CVE-2006-3940webappsphp26 jul 2006
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (2)
CVE-2006-3838remotewindows26 jul 2006
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RIESGO
abrir
Exploit-DBVexDay Proof
eIQnetworks License Manager - Remote Buffer Overflow (Metasploit) (1)
CVE-2006-3838remotewindows26 jul 2006
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RIESGO
abrir
Exploit-DBVexDay Proof
phpBB-Auction 1.x - 'auction_store.php?u' SQL Injection
CVE-2006-3940webappsphp26 jul 2006
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
LinksCaffe 3.0 - 'links.php' Multiple SQL Injections
CVE-2006-3884webappsphp25 jul 2006
Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
LinksCaffe 3.0 - 'menu.inc.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3883webappsphp25 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Pro Bid 5.2.4 - 'categories.php?orderType' SQL Injection
CVE-2006-3926webappsphp25 jul 2006
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Pro Bid 5.2.4 - 'viewfeedback.php' Multiple SQL Injections
CVE-2006-3926webappsphp25 jul 2006
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPSavant Savant2 - 'Stylesheet.php?MosConfig_absolute_path' Remote File Inclusion
CVE-2006-3990webappsphp25 jul 2006
Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree compo
28RIESGO
abrir
Exploit-DBVexDay Proof
LinksCaffe 3.0 - 'counter.php?tablewidth' Cross-Site Scripting
CVE-2006-3883webappsphp25 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Pro Bid 5.2.4 - 'auctionsearch.php?advsrc' Cross-Site Scripting
CVE-2006-3927webappsphp25 jul 2006
Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
LinksCaffe 3.0 - 'links.php?newdays' Cross-Site Scripting
CVE-2006-3883webappsphp25 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
libmikmod 3.2.2 - GT2 Loader Local Heap Overflow (PoC)
CVE-2006-3879dosmultiple25 jul 2006
Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Suite/Firefox < 1.5.0.5 - Navigator Object Code Execution (Metasploit)
CVE-2006-3677remotemultiple25 jul 2006
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by chang
60RIESGO
abrir
Exploit-DBVexDay Proof
Solaris 10 - 'sysinfo()' Local Kernel Memory Disclosure (1)
CVE-2006-3824localsolaris24 jul 2006
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo sys
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/2003 - Remote Denial of Service
CVE-2006-3880doswindows24 jul 2006
Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cau
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Native Function Iterator Denial of Service
CVE-2006-3915doswindows24 jul 2006
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iteratin
28RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Component PrinceClan Chess 0.8 - Remote File Inclusion
CVE-2006-5044webappsphp24 jul 2006
Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla
23RIESGO
abrir
Exploit-DBVexDay Proof
Lussumo Vanilla 1.0 - RootDirectory Remote File Inclusion
CVE-2006-3850webappsphp24 jul 2006
PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php ex
23RIESGO
abrir
anteriorpágina 587 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.