Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Five Star Review Script - 'report.php?item_id' Cross-Site Scripting
CVE-2006-3061webappsphp12 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
SixCMS 6.0 - 'list.php' Cross-Site Scripting
CVE-2006-3051webappsphp12 jun 2006
Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
WinSCP 3.8.1 - URI Handler Arbitrary File Access
CVE-2006-3015remotewindows12 jun 2006
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files
23RIESGO
abrir
Exploit-DBVexDay Proof
Content-Builder (CMS) 0.7.5 - Multiple Include Vulnerabilities
CVE-2006-3172webappsphp11 jun 2006
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary
28RIESGO
abrir
Exploit-DBVexDay Proof
FlexWATCH Network Camera - Cross-Site Scripting
CVE-2006-3603webappsphp11 jun 2006
Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
KAPhotoservice 7.5 - 'albums.asp?albumid' Cross-Site Scripting
CVE-2006-2955webappsasp09 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
KAPhotoservice 7.5 - 'edtalbum.asp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-2955webappsasp09 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
0verkill 0.16 - ASCII-ART Game Remote Integer Overflow Crash (PoC)
CVE-2006-2971doslinux09 jun 2006
Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daem
23RIESGO
abrir
Exploit-DBVexDay Proof
Baby Katie Media VSReal and VScal 1.0 - 'myslideshow.php?title' Cross-Site Scripting
CVE-2006-2986webappsphp09 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) v
23RIESGO
abrir
Exploit-DBVexDay Proof
Baby Katie Media VSReal and VScal 1.0 - 'index.php?lid' Cross-Site Scripting
CVE-2006-2986webappsphp09 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) v
23RIESGO
abrir
Exploit-DBVexDay Proof
KAPhotoservice 7.5 - 'album.asp?cat' Cross-Site Scripting
CVE-2006-2955webappsasp09 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
CMS-Bandits 2.5 - 'spaw_root' Remote File Inclusion
CVE-2006-2928webappsphp08 jun 2006
Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, all
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeType - '.TTF' File Remote Denial of Service
CVE-2006-2661dosmultiple08 jun 2006
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file tha
28RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DWL Series Access-Point 2.10na - Config Disclosure
CVE-2006-2901remotehardware08 jun 2006
The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obta
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeType - '.TTF' File Remote Buffer Overflow
CVE-2006-0747remoteunix08 jun 2006
Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file wi
28RIESGO
abrir
Exploit-DBVexDay Proof
MiraksGalerie 2.62 - 'galsecurity.lib.php?listconfigfile[0]' Remote File Inclusion
CVE-2006-2922webappsphp07 jun 2006
Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Business Management 1.0.3 pl1 - 'user_index.php?tf_lastname' Cross-Site Scripting
CVE-2006-3009webappsphp07 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Calendar Express 2.2 - 'month.php' SQL Injection
CVE-2006-2973webappsphp07 jun 2006
Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
QBik WinGate WWW Proxy Server 6.1.1.1077 - 'POST' Remote Buffer Overflow
CVE-2006-2926remotewindows07 jun 2006
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RIESGO
abrir
Exploit-DBVexDay Proof
Open Business Management 1.0.3 pl1 - 'publication_index.php?tf_lang' Cross-Site Scripting
CVE-2006-3009webappsphp07 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Business Management 1.0.3 pl1 - 'list_index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3009webappsphp07 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
MiraksGalerie 2.62 - 'galimage.lib.php?listconfigfile[0]' Remote File Inclusion
CVE-2006-2922webappsphp07 jun 2006
Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Business Management 1.0.3 pl1 - 'group_index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3009webappsphp07 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Business Management 1.0.3 pl1 - 'company_index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-3009webappsphp07 jun 2006
Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
SpamAssassin spamd 3.1.3 - Command Injection (Metasploit)
CVE-2006-2447remoteunix06 jun 2006
SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute a
60RIESGO
abrir
Exploit-DBVexDay Proof
GANTTy 1.0.3 - 'index.php' Cross-Site Scripting
CVE-2006-2892webappsphp06 jun 2006
Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML a
23RIESGO
abrir
Exploit-DBVexDay Proof
myNewsletter 1.1.2 - 'adminLogin.asp' Authentication Bypass
CVE-2006-2887webappsasp06 jun 2006
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
GD Graphics Library 2.0.33 - Remote Denial of Service
CVE-2006-2906doslinux06 jun 2006
The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.
28RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 1.x - JavaScript Key Filtering
CVE-2006-2894remotelinux06 jun 2006
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.5/6.0/7.0 - JavaScript Key Filtering
CVE-2006-2894remotewindows06 jun 2006
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1
23RIESGO
abrir
anteriorpágina 596 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.