Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
Scout Portal Toolkit 1.3.1 - 'SPT-QuickSearch.php' Cross-Site Scripting
CVE-2005-4196webappsphp12 dic 2005
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
Magic Book Professional 2.0 - 'Book.cfm' Cross-Site Scripting
CVE-2005-4177webappscfm12 dic 2005
Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Sights 'N Sounds Streaming Media Server 2.0.3 - 'SWS.exe' Buffer Overflow
CVE-2005-4194doswindows12 dic 2005
Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cau
23RIESGO
abrir
Exploit-DBVexDay Proof
Scout Portal Toolkit 1.3.1 - 'SPT-AdvancedSearch.php' Cross-Site Scripting
CVE-2005-4196webappsphp12 dic 2005
Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
Alt-N MDaemon WorldClient 8.1.3 - Denial of Service
CVE-2005-4209doswindows12 dic 2005
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inbox
23RIESGO
abrir
Exploit-DBVexDay Proof
LocazoList Classifieds 1.0 - 'SearchDB.asp' Input Validation
CVE-2005-4205webappsasp12 dic 2005
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
phpCOIN 1.2.2 - 'phpcoinsessid' SQL Injection / Remote Code Execution
CVE-2005-4213webappsphp12 dic 2005
SQL injection vulnerability in mod.php in phpCOIN 1.2.2 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
Arab Portal 2.0 - 'Link.php' SQL Injection
CVE-2005-4221webappsphp12 dic 2005
SQL injection vulnerability in link.php in Arab Portal System 2 Beta 2 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
BlackBoard Academic Suite 6.2.3.23 - Frameset.jsp Cross-Domain Frameset Loading
CVE-2005-4206MEDIUMwebappsjsp12 dic 2005
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allow
33RIESGO
abrir
Exploit-DBVexDay Proof
Flatnuke 2.5.6 - Privilege Escalation / Remote Command Execution
CVE-2005-4449webappsphp10 dic 2005
verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the fil
23RIESGO
abrir
Exploit-DBVexDay Proof
Flatnuke 2.5.6 - Privilege Escalation / Remote Command Execution
CVE-2005-4208webappsphp10 dic 2005
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot)
23RIESGO
abrir
Exploit-DBVexDay Proof
Lyris ListManager - Read Message Attachment SQL Injection (Metasploit)
CVE-2005-4143remotewindows09 dic 2005
SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel 95/97/2000/2002/2003/2004 - Malformed Range Memory Corruption
CVE-2005-4131doswindows08 dic 2005
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allo
35RIESGO
abrir
Exploit-DBVexDay Proof
Magic Forum Personal - 'view_forum.cfm?ForumID' SQL Injection
CVE-2005-4071webappscfm08 dic 2005
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Magic Forum Personal - 'view_thread.cfm' Multiple SQL Injections
CVE-2005-4071webappscfm08 dic 2005
Multiple SQL injection vulnerabilities in CFMagic Magic Forum Personal 2.5 and earlier allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
SugarSuite Open Source 4.0beta - Remote Code Execution (2)
CVE-2005-4087webappsphp08 dic 2005
PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (
23RIESGO
abrir
Exploit-DBVexDay Proof
Website Baker 2.6.0 - Authentication Bypass / Remote Code Execution
CVE-2005-4140webappsphp08 dic 2005
SQL injection vulnerability in admin/login/index.php in Website Baker 2.6.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
SugarSuite Open Source 4.0beta - Remote Code Execution (2)
CVE-2005-4086webappsphp08 dic 2005
Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (Suga
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 0.x/1.x - Large History File Buffer Overflow
CVE-2005-4134dosmultiple08 dic 2005
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of ser
28RIESGO
abrir
Exploit-DBVexDay Proof
CF_Nuke 4.6 - 'index.cfm' Cross-Site Scripting
CVE-2005-4075webappscfm08 dic 2005
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in CF_Nuke 4.6 and earlier allow remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
CF_Nuke 4.6 - 'index.cfm' Local File Inclusion
CVE-2005-4074webappscfm08 dic 2005
Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Magic List Pro - 'view_archive.cfm?ListID' SQL Injection
CVE-2005-4073webappscfm08 dic 2005
SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9.2.0.1 - Universal XDB HTTP Pass Overflow (Metasploit)
CVE-2003-0727remotewindows08 dic 2005
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RIESGO
abrir
Exploit-DBVexDay Proof
Nortel SSL VPN 4.2.1.6 - Web Interface Input Validation
CVE-2005-4197webappscgi08 dic 2005
tunnelform.yaws in Nortel SSL VPN 4.2.1.6 allows remote attackers to execute arbitrary commands via a link in the a para
28RIESGO
abrir
Exploit-DBVexDay Proof
MilliScripts 1.4 - 'register.php' Cross-Site Scripting
CVE-2005-4161webappsphp08 dic 2005
Multiple cross-site scripting (XSS) vulnerabilities in MilliScripts 1.4 redirect script allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Check Point VPN-1 SecureClient 4.0 < 4.1 - Policy Bypass
CVE-2005-4093doshardware07 dic 2005
Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to byp
23RIESGO
abrir
Exploit-DBVexDay Proof
DRZES Hms 3.2 - 'login.php' Cross-Site Scripting
CVE-2005-4136webappsphp07 dic 2005
Cross-site scripting (XSS) vulnerability in login.php in DRZES HMS 3.2 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPMForum - 'forum.asp?baslik' SQL Injection
CVE-2005-4141webappsasp07 dic 2005
Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
Thwboard Beta 2.8 - 'v_profile.php?user' SQL Injection
CVE-2005-4139webappsphp07 dic 2005
Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
SugarSuite Open Source 4.0beta - Remote Code Execution (1)
CVE-2005-4086webappsphp07 dic 2005
Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (Suga
23RIESGO
abrir
anteriorpágina 636 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.