Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
Cerberus Helpdesk 2.7 - 'Clients.php' Cross-Site Scripting
CVE-2006-0509webappsphp31 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Metasploit)
CVE-2006-0476remotewindows31 ene 2006
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 1.0/1.5 XBL - MOZ-BINDING Property Cross-Domain Scripting
CVE-2006-0496remotelinux30 ene 2006
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earl
23RIESGO
abrir
Exploit-DBVexDay Proof
sPaiz-Nuke - 'modules.php' Cross-Site Scripting
CVE-2006-0480webappsphp30 ene 2006
Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Daffodil CRM 1.5 - 'Userlogin.asp' SQL Injection
CVE-2006-0510webappsasp30 ene 2006
SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
Ashwebstudio Ashnews 0.83 - Cross-Site Scripting
CVE-2006-0524webappsphp30 ene 2006
Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
PmWiki 2.1 - Multiple Input Validation Vulnerabilities
CVE-2006-0479webappsphp30 ene 2006
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (1)
CVE-2006-0476remotewindows29 ene 2006
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RIESGO
abrir
Exploit-DBVexDay Proof
UBBCentral UBB.Threads 6.3 - 'showflat.php' SQL Injection
CVE-2006-0545webappsphp29 ene 2006
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows re
23RIESGO
abrir
Exploit-DBVexDay Proof
GNOME Evolution 2.2.3/2.3.x - Inline XML File Attachment Buffer Overflow
CVE-2006-0528doslinux28 ene 2006
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a
28RIESGO
abrir
Exploit-DBVexDay Proof
CommuniGate Pro 5.0.6 - Server LDAP Denial of Service
CVE-2006-0468doslinux28 ene 2006
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execu
28RIESGO
abrir
Exploit-DBVexDay Proof
My Little Homepage Products - BBCode Link Tag Script Injection
CVE-2006-0473webappsphp26 ene 2006
Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Database Server 9i/10g - 'XML' Local Buffer Overflow
CVE-2006-0287localwindows26 ene 2006
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server
28RIESGO
abrir
Exploit-DBVexDay Proof
Exiv2 - Corrupted EXIF Data Denial of Service
CVE-2005-4676dosmultiple26 ene 2006
Buffer overflow in Andreas Huggel Exiv2 before 0.9 does not null terminate strings before calling the sscanf function, w
23RIESGO
abrir
Exploit-DBVexDay Proof
AndoNET Blog 2004.9.2 - 'Comentarios.php' SQL Injection
CVE-2006-0462webappsphp26 ene 2006
SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
Phpclanwebsite 1.23.1 - SQL Injection
CVE-2006-0444webappsphp25 ene 2006
SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
SquirrelMail 3.1 - Change Passwd Plugin Local Buffer Overflow
CVE-2006-0331locallinux25 ene 2006
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via lon
23RIESGO
abrir
Exploit-DBVexDay Proof
PMachine ExpressionEngine 1.4.1 - HTTP Referrer HTML Injection
CVE-2006-0461webappsphp25 ene 2006
Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Aironet Wireless Access Points - Memory Exhaustion ARP (Denial of Service)
CVE-2006-0354doshardware25 ene 2006
Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial
28RIESGO
abrir
Exploit-DBVexDay Proof
KarjaSoft Sami FTP Server 2.0.1 - Remote Buffer Overflow (Metasploit)
CVE-2006-0441remotewindows25 ene 2006
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RIESGO
abrir
Exploit-DBVexDay Proof
CheesyBlog 1.0 - Multiple HTML Injection Vulnerabilities
CVE-2006-0443webappsphp25 ene 2006
Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
KarjaSoft Sami FTP Server 2.0.1 - Remote Stack Buffer Overflow
CVE-2006-0441remotewindows25 ene 2006
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RIESGO
abrir
Exploit-DBVexDay Proof
miniBloggie 1.0 - 'login.php' SQL Injection
CVE-2006-0417webappsphp24 ene 2006
SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
creLoaded 6.15 - 'HTMLAREA' Automated Perl
CVE-2006-0478webappsphp24 ene 2006
CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files,
23RIESGO
abrir
Exploit-DBVexDay Proof
123 Flash Chat 5.0 - Remote Code Injection
CVE-2006-0418webappsphp24 ene 2006
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a craft
23RIESGO
abrir
Exploit-DBVexDay Proof
SleeperChat 0.3f - 'index.php' Cross-Site Scripting
CVE-2006-0415webappsphp24 ene 2006
Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
PixelPost 1.4.3 - User Comment HTML Injection
CVE-2006-0409webappsphp24 ene 2006
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.0.1/1.0.2 Notepad - 'usercp.php' HTML Injection
CVE-2006-0442webappsphp24 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
NewsPHP - 'index.php' Multiple SQL Injections
CVE-2006-0413webappsphp23 ene 2006
Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
AZ Bulletin Board 1.0.x/1.1 - 'post.php' HTML Injection
CVE-2006-0407webappsphp23 ene 2006
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attack
23RIESGO
abrir
anteriorpágina 625 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.