Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
BT Voyager 2091 (Wireless ADSL) - Multiple Vulnerabilities
CVE-2006-3561remotehardware18 jul 2006
BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.13 < 2.6.17.4 - 'logrotate prctl()' Local Privilege Escalation
CVE-2006-2451locallinux18 jul 2006
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a l
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Board 2.1 < 2.1.6 - SQL Injection (2)
CVE-2006-7071webappsphp18 jul 2006
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
RARLAB WinRAR 3.x - LHA Filename Handling Buffer Overflow
CVE-2006-3845remotewindows18 jul 2006
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary c
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Component pollxt 1.22.07 - Remote File Inclusion
CVE-2006-5045webappsphp17 jul 2006
Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and at
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Routers - UPNP Buffer Overflow
CVE-2006-3687doshardware17 jul 2006
Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-
28RIESGO
abrir
Exploit-DBVexDay Proof
Agnitum Outpost Firewall 3.5.631 - 'FiltNT.SYS' Local Denial of Service
CVE-2006-3696doswindows17 jul 2006
filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) vi
23RIESGO
abrir
Exploit-DBVexDay Proof
ListMessenger 0.9.3 - 'LM_Path' Remote File Inclusion
CVE-2006-3692webappsphp17 jul 2006
PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Component perForms 1.0 - Remote File Inclusion
CVE-2006-3774webappsphp17 jul 2006
PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joo
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Module Calendar 1.5.7 - 'Com_Calendar.php' Remote File Inclusion
CVE-2006-3843webappsphp17 jul 2006
PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
CVE-2006-3755webappsphp16 jul 2006
PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
Rocks Clusters 4.1 - 'umount-loop' Local Privilege Escalation
CVE-2006-3693locallinux15 jul 2006
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) i
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
CVE-2011-4084webappsphp15 jul 2006
20RIESGO
abrir
Exploit-DBVexDay Proof
Rocks Clusters 4.1 - 'mount-loop' Local Privilege Escalation
CVE-2006-3693locallinux15 jul 2006
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) i
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
CVE-2011-5034webappsphp15 jul 2006
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger ha
60RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
CVE-2011-5035webappsphp15 jul 2006
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 a
50RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
CVE-2011-4885webappsphp15 jul 2006
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions pre
60RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
CVE-2011-4858webappsphp15 jul 2006
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without r
60RIESGO
abrir
Exploit-DBVexDay Proof
Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure
CVE-2006-3392remotemultiple15 jul 2006
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.1.5 - 'CLIENT-IP' SQL Injection
CVE-2006-3775webappsphp15 jul 2006
SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Sunbelt Kerio Personal Firewall 4.3.426 - CreateRemoteThread Denial of Service
CVE-2006-3787doshardware15 jul 2006
kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API fun
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft PowerPoint 2003 - 'mso.dll' '.PPT' Processing Code Execution
CVE-2006-3655remotewindows14 jul 2006
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary co
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (4)
CVE-2006-2451locallinux14 jul 2006
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a l
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft PowerPoint 2003 - '.ppt' File Closure Memory Corruption
CVE-2006-3656remotewindows14 jul 2006
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a c
28RIESGO
abrir
Exploit-DBVexDay Proof
KDE Konqueror 3.5.x - ReplaceChild Denial of Service
CVE-2006-3672doslinux14 jul 2006
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft PowerPoint 2003 - 'powerpnt.exe' Remote Overflow
CVE-2006-3660remotewindows14 jul 2006
Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to po
28RIESGO
abrir
Exploit-DBVexDay Proof
Subberz Lite - UserFunc Remote File Inclusion
CVE-2006-3689webappsphp14 jul 2006
PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (3)
CVE-2006-2451locallinux13 jul 2006
The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a l
23RIESGO
abrir
Exploit-DBVexDay Proof
PhotoCycle 1.0 - 'PhotoCycle.php' Cross-Site Scripting
CVE-2006-3680webappsphp13 jul 2006
Cross-site scripting (XSS) vulnerability in photocycle in Photocycle 1.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
FlatNuke 2.5.7 - 'index.php' Remote File Inclusion
CVE-2006-3608webappsphp13 jul 2006
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the
23RIESGO
abrir
anteriorpágina 589 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.