Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
Subdreamer 2.2.1 - SQL Injection / Command Execution
CVE-2005-3423webappsphp31 oct 2005
Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPCafe Tutorial Manager - 'index.php' SQL Injection
CVE-2005-3478webappsphp31 oct 2005
SQL injection vulnerability in index.php in PHPCafe.net Tutorials Manager 1.0 Beta 2 allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 4.x/5.0.x - Arbitrary File Upload GLOBAL Variable Overwrite
CVE-2005-3390remotephp31 oct 2005
The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows rem
35RIESGO
abrir
Exploit-DBVexDay Proof
Snitz Forum 2000 - 'post.asp' Cross-Site Scripting
CVE-2005-3411webappsasp31 oct 2005
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
phpFaber CMS 1.3.36 - 'Htmlarea.php' Cross-Site Scripting
CVE-2006-5626webappsphp30 oct 2005
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (C
23RIESGO
abrir
Exploit-DBVexDay Proof
MG2 0.5.1 - Authentication Bypass
CVE-2005-3432webappsphp29 oct 2005
MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list
23RIESGO
abrir
Exploit-DBVexDay Proof
Hasbani-WindWeb/2.0 - GET Remote Denial of Service
CVE-2005-3475doshardware27 oct 2005
Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted G
23RIESGO
abrir
Exploit-DBVexDay Proof
ASP Fast Forum - 'error.asp' Cross-Site Scripting
CVE-2005-3422webappsasp27 oct 2005
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.x - 'body_header.inc.php?section' Local File Inclusion
CVE-2005-3404webappsphp27 oct 2005
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrar
28RIESGO
abrir
Exploit-DBVexDay Proof
Novell ZENworks Patch Management 6.0.52 - '/computers/default.asp?Direction' SQL Injection
CVE-2005-3315webappsasp27 oct 2005
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.x - 'print.php?section' Remote File Inclusion
CVE-2005-3404webappsphp27 oct 2005
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrar
28RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 1.x - 'forum.inc.php' Arbitrary Command Execution
CVE-2005-3405webappsphp27 oct 2005
ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell ZENworks Patch Management 6.0.52 - '/reports/default.asp' Multiple SQL Injections
CVE-2005-3315webappsasp27 oct 2005
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
saPHP Lesson - 'add.php?forumid' SQL Injection
CVE-2005-3363webappsphp26 oct 2005
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - 'Bluez' BlueTooth Signed Buffer Index Privilege Escalation (2)
CVE-2005-0750locallinux26 oct 2005
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
23RIESGO
abrir
Exploit-DBVexDay Proof
Belchior Foundry VCard 2.9 - Remote File Inclusion
CVE-2005-3332webappsphp26 oct 2005
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - 'Bluez' BlueTooth Signed Buffer Index Privilege Escalation (2)
CVE-2005-1294locallinux26 oct 2005
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Snoopy 0.9x/1.0/1.2 - Arbitrary Command Execution
CVE-2005-3330remotewindows26 oct 2005
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4)
28RIESGO
abrir
Exploit-DBVexDay Proof
MyBulletinBoard (MyBB) 1.0 - 'usercp.php' SQL Injection
CVE-2005-3326webappsphp26 oct 2005
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
IPBProArcade 2.5.2 - 'GameID' SQL Injection
CVE-2005-4702webappsphp26 oct 2005
SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Search Enhanced Module 1.1/2.0 - HTML Injection
CVE-2005-3368webappsphp26 oct 2005
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Woltlab 1.1/2.x - 'Info-DB Info_db.php' Multiple SQL Injections
CVE-2005-3369webappsphp26 oct 2005
Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allo
23RIESGO
abrir
Exploit-DBVexDay Proof
GCards 1.43 - 'news.php' SQL Injection
CVE-2005-3408webappsphp26 oct 2005
SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
RSA ACE Agent 5.x - Image Cross-Site Scripting
CVE-2005-3329webappscgi26 oct 2005
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Flyspray 0.9 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3334webappsphp26 oct 2005
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
TClanPortal 1.1.3 - 'id' SQL Injection
CVE-2005-4656webappsphp26 oct 2005
SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
Basic Analysis and Security Engine (BASE) 1.2 - 'Base_qry_main.php' SQL Injection
CVE-2005-3325webappsphp25 oct 2005
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6
23RIESGO
abrir
Exploit-DBVexDay Proof
Snort 2.4.2 - Back Orifice Parsing Remote Buffer Overflow
CVE-2005-3252remotelinux25 oct 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RIESGO
abrir
Exploit-DBVexDay Proof
SiteTurn Domain Manager Pro - Admin Panel Cross-Site Scripting
CVE-2005-3320webappsphp24 oct 2005
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Nuked-klaN 1.7 Links Module - 'link_id' SQL Injection
CVE-2005-3305webappsphp24 oct 2005
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
anteriorpágina 647 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.