Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Nukedit 4.9.6 - Unauthorized Admin Add
CVE-2006-2737webappsasp29 may 2006
utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary gro
23RIESGO
abrir
Exploit-DBVexDay Proof
Mini-NUKE 2.3 - 'Your_Account.asp' Multiple SQL Injections
CVE-2006-2732webappsasp29 may 2006
SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Alt-N MDaemon 2-8 - IMAP Remote Buffer Overflow
CVE-2006-2646doswindows29 may 2006
Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a lo
23RIESGO
abrir
Exploit-DBVexDay Proof
Photoalbum B&W 1.3 - 'index.php' Cross-Site Scripting
CVE-2006-2728webappsphp29 may 2006
Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPBB 0.5.2 - 'Perform_search.asp' Cross-Site Scripting
CVE-2006-2648webappsasp29 may 2006
Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Speedy ASP Forum - 'profileupdate.asp' User Pass Change
CVE-2006-2807webappsasp29 may 2006
ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified acco
23RIESGO
abrir
Exploit-DBVexDay Proof
tinyBB 0.3 - Remote File Inclusion / SQL Injection
CVE-2006-2740webappsphp28 may 2006
Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
EggBlog < 3.07 - Remote SQL Injection / Privilege Escalation
CVE-2006-2725webappsphp28 may 2006
SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
Enigma Haber 4.3 - Multiple SQL Injections
CVE-2006-2731webappsasp28 may 2006
Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
F@cile Interactive Web 0.8x - Remote File Inclusion / Cross-Site Scripting
CVE-2006-2745webappsphp28 may 2006
Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is
23RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 5.x/6.x - Multiple Remote File Inclusions
CVE-2006-2755webappsphp28 may 2006
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Activity MOD Plus 1.1.0 - 'phpBB Mod' File Inclusion
CVE-2006-2735webappsphp28 may 2006
PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as
23RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 5.x/6.x - Multiple Remote File Inclusions
CVE-2006-2675webappsphp28 may 2006
PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPSitem 2.0 - SQL Injection / Database Disclosure
CVE-2006-2793webappsasp28 may 2006
SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Blend Portal 1.2.0 - 'phpBB Mod' Remote File Inclusion
CVE-2006-2736webappsphp28 may 2006
PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when re
23RIESGO
abrir
Exploit-DBVexDay Proof
tinyBB 0.3 - Remote File Inclusion / SQL Injection
CVE-2006-2739webappsphp28 may 2006
PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allo
23RIESGO
abrir
Exploit-DBVexDay Proof
CosmicShoppingCart - 'search.php' SQL Injection
CVE-2006-2650webappsphp28 may 2006
SQL injection vulnerability in cosmicshop/search.php in CosmicShoppingCart allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
F@cile Interactive Web 0.8x - Remote File Inclusion / Cross-Site Scripting
CVE-2006-2744webappsphp28 may 2006
PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
F@cile Interactive Web 0.8x - Remote File Inclusion / Cross-Site Scripting
CVE-2006-2746webappsphp28 may 2006
Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPSitem 2.0 - SQL Injection / Database Disclosure
CVE-2006-2794webappsasp28 may 2006
Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified i
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1191doswindows27 may 2006
Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a brows
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1189doswindows27 may 2006
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1245doswindows27 may 2006
Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote a
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1359doswindows27 may 2006
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1190doswindows27 may 2006
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamicall
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1388doswindows27 may 2006
Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown ve
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1186doswindows27 may 2006
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1192doswindows27 may 2006
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address b
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1188doswindows27 may 2006
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a ce
35RIESGO
abrir
Exploit-DBVexDay Proof
Chipmunk Directory - 'index.php' Cross-Site Scripting
CVE-2006-7042webappsphp27 may 2006
Cross-site scripting (XSS) vulnerability in directory/index.php in Chipmunk directory allows remote attackers to inject
23RIESGO
abrir
anteriorpágina 599 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.