Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Microsoft Internet Explorer - HTML Tag Memory Corruption (MS06-013)
CVE-2006-1191doswindows27 may 2006
Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a brows
35RIESGO
abrir
Exploit-DBVexDay Proof
qjForum - 'member.asp' SQL Injection
CVE-2006-2638webappsasp26 may 2006
SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the u
23RIESGO
abrir
Exploit-DBVexDay Proof
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
CVE-2006-2645webappsphp26 may 2006
PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
CVE-2006-2697webappsasp26 may 2006
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
tiffsplit (libtiff 3.8.2) - Local Stack Buffer Overflow
CVE-2006-2656locallinux26 may 2006
Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute
28RIESGO
abrir
Exploit-DBVexDay Proof
Easy-Content Forums 1.0 - Multiple SQL Injection / Cross-Site Scripting Vulnerabilities
CVE-2006-2696webappsasp26 may 2006
Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
Exploit-DBVexDay Proof
Plume CMS 1.0.3 - 'manager_path' Remote File Inclusion
CVE-2006-0725webappsphp26 may 2006
PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Board 2.0/2.1 - 'index.php?CK' SQL Injection
CVE-2006-2061webappsphp25 may 2006
SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 al
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.0.2 - 'cache' Remote Shell Injection
CVE-2006-2667webappsphp25 may 2006
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary c
28RIESGO
abrir
Exploit-DBVexDay Proof
Socketmail 2.2.6 - 'site_path' Remote File Inclusion
CVE-2006-2681webappsphp25 may 2006
PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_qu
23RIESGO
abrir
Exploit-DBVexDay Proof
netPanzer 0.8 rev 952 - 'frameNum' Server Terminiation
CVE-2006-2575dosmultiple23 may 2006
The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir
Exploit-DBVexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
CVE-2006-2577webappsphp23 may 2006
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RIESGO
abrir
Exploit-DBVexDay Proof
AZ Photo Album Script Pro - Cross-Site Scripting
CVE-2006-2680webappsphp23 may 2006
Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Dia 0.8x/0.9x - Filename Remote Format String
CVE-2006-2480doslinux23 may 2006
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly
23RIESGO
abrir
Exploit-DBVexDay Proof
PunkBuster < 1.229 - WebTool Service Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-2587dosmultiple23 may 2006
Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products includ
23RIESGO
abrir
Exploit-DBVexDay Proof
Nucleus CMS 3.22 - 'DIR_LIBS' Remote File Inclusion
CVE-2006-2583webappsphp23 may 2006
PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
Prodder 0.4 - Arbitrary Shell Command Execution
CVE-2006-2548remotelinux22 may 2006
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacter
28RIESGO
abrir
Exploit-DBVexDay Proof
Cyrus IMAPD 2.3.2 - 'pop3d' Remote Buffer Overflow (1)
CVE-2006-2502remotelinux21 may 2006
Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allow
50RIESGO
abrir
Exploit-DBVexDay Proof
CodeAvalanche News 1.2 - 'default.asp' SQL Injection
CVE-2006-2499webappsasp19 may 2006
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
CVE-2006-2528webappsphp19 may 2006
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Artmedic NewsLetter 4.1 - 'Log.php' Remote Script Execution
CVE-2006-2608webappsphp19 may 2006
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify
23RIESGO
abrir
Exploit-DBVexDay Proof
phpBazar 2.1.0 - Remote File Inclusion / Authentication Bypass
CVE-2006-2527webappsphp19 may 2006
Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unau
23RIESGO
abrir
Exploit-DBVexDay Proof
JemWeb DownloadControl 1.0 - 'DC.php' SQL Injection
CVE-2006-2552webappsphp19 may 2006
Jemscripts DownloadControl 1.0 allows remote attackers to obtain sensitive information via an invalid dcid parameter to
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPBB 0.5.2 - 'default.asp?action' Cross-Site Scripting
CVE-2006-2497webappsasp18 may 2006
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Cosmoshop 8.10.78/8.11.106 - 'Lshop.cgi' SQL Injection
CVE-2006-2474webappscgi18 may 2006
SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPBB 0.5.2 - 'profile.asp?get' Cross-Site Scripting
CVE-2006-2497webappsasp18 may 2006
Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
obotix IP Camera M1 1.9.4 .7/M10 2.0.5.2 - help Script Cross-Site Scripting
CVE-2006-2490remotehardware17 may 2006
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other
23RIESGO
abrir
Exploit-DBVexDay Proof
Quezza BB 1.0 - 'quezza_root_path' File Inclusion
CVE-2006-2485webappsphp17 may 2006
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 all
23RIESGO
abrir
Exploit-DBVexDay Proof
obotix IP Camera M1 1.9.4 .7/M10 2.0.5.2 - 'events.tar?source_ip' Cross-Site Scripting
CVE-2006-2490remotehardware17 may 2006
Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other
23RIESGO
abrir
Exploit-DBVexDay Proof
BoastMachine 3.1 - 'admin.php' Cross-Site Scripting
CVE-2006-2491webappsphp17 may 2006
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earli
23RIESGO
abrir
anteriorpágina 600 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.