Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
PHP-Nuke 7.8 Search Module - SQL Injection
CVE-2005-3792webappsphp16 nov 2005
Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with
35RIESGO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'msg'/'forum' SQL Injection
CVE-2005-4226webappsphp16 nov 2005
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'forum' SQL Injection
CVE-2005-4226webappsphp16 nov 2005
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Ekinboard 1.0.3 - 'profile.php' Cross-Site Scripting
CVE-2005-3638webappsphp15 nov 2005
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or H
23RIESGO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.exe?sug' Cross-Site Scripting
CVE-2005-3577webappscgi15 nov 2005
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPWCMS 1.2.5 -DEV - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3790webappsphp15 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote File Inclusion
CVE-2005-3797webappsphp15 nov 2005
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.exe?tsurl' Arbitrary Article Access
CVE-2005-3576webappscgi15 nov 2005
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the articl
23RIESGO
abrir
Exploit-DBVexDay Proof
Pearl Forums 2.0 - 'index.php' Multiple SQL Injections
CVE-2005-4647webappsphp15 nov 2005
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPWCMS 1.2.5 -DEV - 'imgdir' Traversal Arbitrary File Access
CVE-2005-3789webappsphp15 nov 2005
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (d
23RIESGO
abrir
Exploit-DBVexDay Proof
Pearl Forums 2.0 - 'index.php' Local File Inclusion
CVE-2005-4646webappsphp15 nov 2005
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPWCMS 1.2.5 -DEV - 'login.php?form_lang' Traversal Arbitrary File Access
CVE-2005-3789webappsphp15 nov 2005
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (d
23RIESGO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.cgi' File Existence Enumeration
CVE-2005-3579webappscgi15 nov 2005
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the qu
23RIESGO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.exe?sug' SQL Injection
CVE-2005-3578webappscgi15 nov 2005
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Codegrrl - 'Protection.php' Code Execution
CVE-2005-3571webappsphp14 nov 2005
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently
23RIESGO
abrir
Exploit-DBVexDay Proof
Wizz Forum - 'ForumAuthDetails.php?AuthID' SQL Injection
CVE-2005-3682webappsphp14 nov 2005
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir
Exploit-DBVexDay Proof
Wizz Forum - 'forumreply.php?TopicID' SQL Injection
CVE-2005-3682webappsphp14 nov 2005
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir
Exploit-DBVexDay Proof
Cyphor 0.19 - 'show.php?id' SQL Injection
CVE-2005-3575webappsphp14 nov 2005
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Wizz Forum 1.20 - 'TopicID' SQL Injection
CVE-2005-3682webappsphp14 nov 2005
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir
Exploit-DBVexDay Proof
Arki-DB 1.0 - 'catid' SQL Injection
CVE-2005-3696webappsphp14 nov 2005
SQL injection vulnerability in Arki-DB 1.0 and 2.0 allows remote attackers to execute arbitrary SQL commands via the cat
23RIESGO
abrir
Exploit-DBVexDay Proof
Help Center Live 1.0/1.2/2.0 - 'module.php' Local File Inclusion
CVE-2005-3639webappsphp14 nov 2005
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to acce
23RIESGO
abrir
Exploit-DBVexDay Proof
Unclassified NewsBoard 1.5.3 Patch 3 - Blind SQL Injection
CVE-2005-3686webappsphp14 nov 2005
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
ActiveCampaign 1-2-All Broadcast Email 4.0 - Admin Control Panel 'Username' SQL Injection
CVE-2005-3679webappsphp12 nov 2005
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'download.php?File' SQL Injection
CVE-2005-3676webappsphp12 nov 2005
SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Veritas Storage Foundation 4.0 - VCSI18N_LANG Local Overflow
CVE-2005-3566locallinux12 nov 2005
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
XOOPS (wfdownloads) 2.05 Module - Multiple Vulnerabilities
CVE-2005-3681webappsphp12 nov 2005
SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Snort 2.4.2 - Back Orifice Pre-Preprocessor Remote (3)
CVE-2005-3252remotewindows11 nov 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RIESGO
abrir
Exploit-DBVexDay Proof
Sudo Perl 1.6.x - Environment Variable Handling Security Bypass
CVE-2005-4158locallinux11 nov 2005
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT e
23RIESGO
abrir
Exploit-DBVexDay Proof
Snort 2.4.2 - Back Orifice Pre-Preprocessor Remote (4)
CVE-2005-3252remotelinux11 nov 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RIESGO
abrir
Exploit-DBVexDay Proof
RealNetworks RealOne Player/RealPlayer - '.RM' Local Stack Buffer Overflow
CVE-2005-2629localwindows10 nov 2005
Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remo
28RIESGO
abrir
anteriorpágina 644 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.