Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
Faq-O-Matic 2.711 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0251webappscgi16 ene 2006
Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat / Geronimo 1.0 - 'Sample Script cal2.jsp?time' Cross-Site Scripting
CVE-2006-0254remotemultiple16 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary we
35RIESGO
abrir
Exploit-DBVexDay Proof
CounterPath eyeBeam 1.1 build 3010n - SIP Header Data Remote Buffer Overflow (2)
CVE-2006-0359doswindows15 ene 2006
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device cr
23RIESGO
abrir
Exploit-DBVexDay Proof
HomeFtp 1.1 - 'NLST' Denial of Service
CVE-2006-0355doswindows14 ene 2006
Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a lo
23RIESGO
abrir
Exploit-DBVexDay Proof
Ultimate Auction 3.67 - Item.pl Cross-Site Scripting
CVE-2006-0217webappscgi14 ene 2006
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Farmers WIFE 4.4 sp1 - 'FTP' Remote System Access
CVE-2006-0319remotewindows14 ene 2006
Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
MiniNuke 1.8.2 - 'hid' SQL Injection
CVE-2006-0199webappsasp14 ene 2006
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
MiniNuke 1.8.2 - Multiple SQL Injections
CVE-2006-0199webappsasp14 ene 2006
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Alstrasoft Template Seller Pro 3.25 - 'Fullview.php' Cross-Site Scripting
CVE-2006-0222webappsphp13 ene 2006
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
Web Host Automation Ltd. Helm 3.2.8 - 'ForgotPassword.asp' Cross-Site Scripting
CVE-2006-0211webappsasp13 ene 2006
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows re
23RIESGO
abrir
Exploit-DBVexDay Proof
Xmame 0.102 - 'lang' Local Buffer Overflow
CVE-2006-0176locallinux13 ene 2006
Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow loc
23RIESGO
abrir
Exploit-DBVexDay Proof
Interspire TrackPoint NX - 'index.php' Cross-Site Scripting
CVE-2006-0210webappsphp12 ene 2006
Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Visual Studio - UserControl Remote Code Execution (2)
CVE-2006-0187remotewindows12 ene 2006
By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserCon
28RIESGO
abrir
Exploit-DBVexDay Proof
Fog Creek Software FogBugz 4.0 29 - 'default.asp' Cross-Site Scripting
CVE-2006-0194webappsasp12 ene 2006
Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Visual Studio - UserControl Remote Code Execution (1)
CVE-2006-0187remotewindows12 ene 2006
By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserCon
28RIESGO
abrir
Exploit-DBVexDay Proof
eStara SoftPhone 3.0.1.46 - SIP Remote Buffer Overflow (2)
CVE-2006-0189remotewindows12 ene 2006
Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a lo
28RIESGO
abrir
Exploit-DBVexDay Proof
eStara SoftPhone 3.0.1.46 - SIP Remote Buffer Overflow (1)
CVE-2006-0189remotewindows12 ene 2006
Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a lo
28RIESGO
abrir
Exploit-DBVexDay Proof
TankLogger 2.4 General Functions Script - SQL Injection
CVE-2006-0209webappsphp12 ene 2006
SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
MyPHPim - Login Page pass Field SQL Injection
CVE-2006-0167webappsphp11 ene 2006
SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_i
23RIESGO
abrir
Exploit-DBVexDay Proof
MyPHPim - 'calendar.php3?cal_id' SQL Injection
CVE-2006-0167webappsphp11 ene 2006
SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_i
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime 6.4/6.5/7.0.x - PictureViewer '.JPEG'/.PICT' File Buffer Overflow
CVE-2005-2340doswindows11 ene 2006
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a craft
28RIESGO
abrir
Exploit-DBVexDay Proof
CounterPath eyeBeam 1.1 build 3010n - SIP Header Data Remote Buffer Overflow (1)
CVE-2006-0359doswindows11 ene 2006
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device cr
23RIESGO
abrir
Exploit-DBVexDay Proof
WebWiz Forums - 'Search_form.asp' Cross-Site Scripting
CVE-2006-0175webappsasp10 ene 2006
Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Orjinweb - 'index.php' Remote File Inclusion
CVE-2006-0171webappsphp10 ene 2006
PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary c
23RIESGO
abrir
Exploit-DBVexDay Proof
Hummingbird Collaboration - Application Cookie Internal Network Information Disclosure
CVE-2006-0174webappscgi10 ene 2006
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain
23RIESGO
abrir
Exploit-DBVexDay Proof
Cray UNICOS /usr/bin/script - Command Line Argument Local Overflow
CVE-2006-0177locallinux10 ene 2006
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/scr
23RIESGO
abrir
Exploit-DBVexDay Proof
Cray UNICOS /etc/nu - '-c' Option Filename Processing Local Overflow
CVE-2006-0177locallinux10 ene 2006
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/scr
23RIESGO
abrir
Exploit-DBVexDay Proof
Xmame 0.102 - '-lang' Local Buffer Overflow
CVE-2006-0176locallinux10 ene 2006
Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow loc
23RIESGO
abrir
Exploit-DBVexDay Proof
Hummingbird Collaboration - Crafted URL File Property Obscuration Download
CVE-2006-0173webappscgi10 ene 2006
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepr
23RIESGO
abrir
Exploit-DBVexDay Proof
Sudo 1.6.x - Environment Variable Handling Security Bypass (1)
CVE-2005-4158locallinux09 ene 2006
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT e
23RIESGO
abrir
anteriorpágina 627 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.