Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
EZDatabase 2.0 - 'db_id' Remote Command Execution
CVE-2006-0214webappsphp22 ene 2006
Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the
23RIESGO
abrir
Exploit-DBVexDay Proof
BlogPHP 1.2 - Multiple SQL Injections
CVE-2006-0372webappsphp20 ene 2006
Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Rockliffe MailSite 5.3.4/6.1.22/7.0.3 - HTTP Mail Management Cross-Site Scripting
CVE-2006-0341webappscgi20 ene 2006
Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
TFTPD32 2.81 - GET Format String Denial of Service (PoC)
CVE-2006-0328doswindows19 ene 2006
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string speci
23RIESGO
abrir
Exploit-DBVexDay Proof
WebspotBlogging 3.0 - 'login.php' SQL Injection
CVE-2006-0324webappsphp19 ene 2006
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 4.x - CREATE Temporary TABLE Symlink Privilege Escalation
CVE-2005-0711remotemultiple18 ene 2006
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allo
23RIESGO
abrir
Exploit-DBVexDay Proof
EggBlog 2.0 - 'message' Cross-Site Scripting
CVE-2006-0350webappsphp18 ene 2006
Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML vi
23RIESGO
abrir
Exploit-DBVexDay Proof
EggBlog 2.0 - 'id' SQL Injection
CVE-2006-0349webappsphp18 ene 2006
SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id paramete
23RIESGO
abrir
Exploit-DBVexDay Proof
SaralBlog 1.0 - Multiple Input Validation Vulnerabilities
CVE-2006-0345webappsphp18 ene 2006
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
microBlog 2.0 - 'index.php' Multiple SQL Injections
CVE-2006-0234webappsphp17 ene 2006
SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
Computer Associates Unicenter 6.0 - Remote Control DM Primer Remote Denial of Service
CVE-2006-0306doswindows17 ene 2006
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup
28RIESGO
abrir
Exploit-DBVexDay Proof
pcAnywhere 8.0/9.0/11.x - Authentication Denial of Service
CVE-2005-3934doswindows17 ene 2006
Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a
23RIESGO
abrir
Exploit-DBVexDay Proof
PowerPortal 1.1/1.3 - 'search.php' Cross-Site Scripting
CVE-2006-0358webappsphp17 ene 2006
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
aoblogger 2.3 - URL BBcode Cross-Site Scripting
CVE-2006-0310webappsphp17 ene 2006
Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a j
23RIESGO
abrir
Exploit-DBVexDay Proof
aoblogger 2.3 - 'login.php?Username' SQL Injection
CVE-2006-0311webappsphp17 ene 2006
SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
PowerPortal 1.1/1.3 - 'index.php' Cross-Site Scripting
CVE-2006-0358webappsphp17 ene 2006
Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
aoblogger 2.3 - 'create.php' Entry Creation
CVE-2006-0312webappsphp17 ene 2006
create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Geronimo 1.0 - Error Page Cross-Site Scripting
CVE-2006-0254remotemultiple16 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary we
35RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat / Geronimo 1.0 - 'Sample Script cal2.jsp?time' Cross-Site Scripting
CVE-2006-0254remotemultiple16 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary we
35RIESGO
abrir
Exploit-DBVexDay Proof
White Album 2.5 - 'Pictures.php' SQL Injection
CVE-2006-0235webappsphp16 ene 2006
SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir para
23RIESGO
abrir
Exploit-DBVexDay Proof
SimpleBlog 2.1 - Multiple Input Validation Vulnerabilities
CVE-2006-0240webappsasp16 ene 2006
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Exploit-DBVexDay Proof
Ultimate Auction 3.67 - ItemList.pl Cross-Site Scripting
CVE-2006-0217webappscgi16 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPXplorer 0.9.33 - 'Workspaces.php' Directory Traversal
CVE-2006-0244webappsphp16 ene 2006
Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Bit 5 Blog 8.1 - 'index.php' SQL Injection
CVE-2006-0320webappsphp16 ene 2006
SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
Cerberus FTP Server 2.32 - Denial of Service
CVE-2006-0357doswindows16 ene 2006
Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified d
23RIESGO
abrir
Exploit-DBVexDay Proof
Veritas NetBackup 4/5 - Volume Manager Daemon Remote Buffer Overflow
CVE-2005-3116remotewindows16 ene 2006
Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterpri
28RIESGO
abrir
Exploit-DBVexDay Proof
GTP iCommerce - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0237webappsphp16 ene 2006
Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
BlogPHP 1.0 - 'index.php' SQL Injection
CVE-2006-0318webappsphp16 ene 2006
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
EZDatabase 2.1.1 - 'index.php' Cross-Site Scripting
CVE-2006-0315webappsphp16 ene 2006
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php
23RIESGO
abrir
Exploit-DBVexDay Proof
Faq-O-Matic 2.711 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0251webappscgi16 ene 2006
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web
23RIESGO
abrir
anteriorpágina 626 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.