Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Extcalendar 2.0 - 'Extcalendar.php' Remote File Inclusion
CVE-2006-3556webappsphp07 jul 2006
PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
AdPlug 2.0 - Multiple Remote File Buffer Overflow Vulnerabilities
CVE-2006-3581remotelinux06 jul 2006
Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execut
28RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.5.x - 'create_course.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3484webappsphp06 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.5.x - '/documentation/admin/index.php' Cross-Site Scripting
CVE-2006-3484webappsphp06 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.5.x - 'password_reminder.php?forgot' Cross-Site Scripting
CVE-2006-3484webappsphp06 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.5.x - '/users/browse.php?cat' Cross-Site Scripting
CVE-2006-3484webappsphp06 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Structured Graphics Control Denial of Service
CVE-2006-3427doswindows06 jul 2006
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL at
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel 2000-2004 - Style Handling and Repair Remote Code Execution
CVE-2006-3431remotewindows06 jul 2006
Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arb
28RIESGO
abrir
Exploit-DBVexDay Proof
Kaillera 0.86 - Message Buffer Overflow
CVE-2006-3491remotewindows06 jul 2006
Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.5.x - '/admin/fix_content.php?submit' Cross-Site Scripting
CVE-2006-3484webappsphp06 jul 2006
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Hosting Controller 6.1 Hotfix 3.1 - Privilege Escalation
CVE-2006-3147webappsasp06 jul 2006
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gai
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 1.x/2.x - Multiple SQL Injections
CVE-2006-3543webappsphp05 jul 2006
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
LifeType 1.0.5 - 'index.php?Date' SQL Injection
CVE-2006-3577webappsphp05 jul 2006
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari Web Browser 2.0.4 - DHTML SetAttributeNode() Null Dereference Denial of Service
CVE-2006-3372dososx05 jul 2006
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttribu
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - Href Title Denial of Service
CVE-2006-3472doswindows04 jul 2006
Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with a
28RIESGO
abrir
Exploit-DBVexDay Proof
PHPWebGallery 1.x - 'comments.php' Cross-Site Scripting
CVE-2006-3476webappsphp04 jul 2006
Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows
23RIESGO
abrir
Exploit-DBVexDay Proof
ImgSvr 0.6.5 - POST Denial of Service
CVE-2006-3546doswindows04 jul 2006
Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via
23RIESGO
abrir
Exploit-DBVexDay Proof
Randshop 0.9.3/1.2 - 'index.php' Remote File Inclusion
CVE-2006-3374webappsphp04 jul 2006
PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'index.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
Gentoo-Specific MPG123 - URI Remote Buffer Overflow
CVE-2006-3355doslinux03 jul 2006
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'faq.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - ADODB.Recordset Filter Property Denial of Service
CVE-2006-3354doswindows03 jul 2006
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter propert
28RIESGO
abrir
Exploit-DBVexDay Proof
Vincent Leclercq News 5.2 - Cross-Site Scripting
CVE-2006-3385webappsphp03 jul 2006
Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'contact.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'delete.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
Plume CMS 1.0.4 - 'search.php?_PX_config[manager_path]' Remote File Inclusion
CVE-2006-3562webappsphp03 jul 2006
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'history.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'features.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Exploit-DBVexDay Proof
Glossaire 1.7 - Remote File Inclusion
CVE-2006-3363webappsphp03 jul 2006
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
free QBoard 1.1 - 'about.php?qb_path' Remote File Inclusion
CVE-2006-3475webappsphp03 jul 2006
Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
anteriorpágina 591 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.