Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
SiteTurn Domain Manager Pro - Admin Panel Cross-Site Scripting
CVE-2005-3320webappsphp24 oct 2005
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Nuked-klaN 1.7 Forum Module - Multiple SQL Injections
CVE-2005-3305webappsphp24 oct 2005
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
Nuked-klaN 1.7 Links Module - 'link_id' SQL Injection
CVE-2005-3305webappsphp24 oct 2005
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Plug-and-Play - 'Umpnpmgr.dll' Denial of Service (MS05-047) (2)
CVE-2005-2120doswindows24 oct 2005
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1
50RIESGO
abrir
Exploit-DBVexDay Proof
Zomplog 3.3/3.4 - 'detail.php' HTML Injection
CVE-2005-3308webappsphp22 oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
FlatNuke 2.5.x - 'index.php' Multiple Remote File Inclusions
CVE-2005-3307webappsphp22 oct 2005
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Plug-and-Play - 'Umpnpmgr.dll' Denial of Service (MS05-047) (1)
CVE-2005-2120doswindows21 oct 2005
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - IPv6 Local Denial of Service
CVE-2005-2973doslinux20 oct 2005
The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
Chipmunk Forum - 'recommend.php?ID' Cross-Site Scripting
CVE-2005-3515webappsphp20 oct 2005
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Veritas NetBackup 6.0 (Linux) - 'bpjava-msvc' Remote Command Execution
CVE-2005-2715remotemultiple20 oct 2005
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Busin
35RIESGO
abrir
Exploit-DBVexDay Proof
Veritas NetBackup 6.0 (Windows x86) - 'bpjava-msvc' Remote Command Execution
CVE-2005-2715remotewindows_x8620 oct 2005
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Busin
35RIESGO
abrir
Exploit-DBVexDay Proof
XMail 1.21 - '-t' Command Line Option Local Buffer Overflow / Local Privilege Escalation
CVE-2005-2943locallinux20 oct 2005
Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a lon
28RIESGO
abrir
Exploit-DBVexDay Proof
Chipmunk Forum - 'quote.php?forumID' Cross-Site Scripting
CVE-2005-3514webappsphp20 oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Veritas NetBackup 6.0 (OSX) - 'bpjava-msvc' Remote Command Execution
CVE-2005-2715remoteosx20 oct 2005
Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Busin
35RIESGO
abrir
Exploit-DBVexDay Proof
Ethereal 0.9.1 < 0.10.12 SLIMP3 - Remote Buffer Overflow (PoC)
CVE-2005-3243doswindows20 oct 2005
Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unk
28RIESGO
abrir
Exploit-DBVexDay Proof
Chipmunk Forum - 'newtopic.php?forumID' Cross-Site Scripting
CVE-2005-3514webappsphp20 oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Chipmunk Directory - 'recommend.php?entryID' Cross-Site Scripting
CVE-2005-3516webappsphp20 oct 2005
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Xerver 4.17 - Single Dot File Request Source Disclosure
CVE-2005-3293remotewindows19 oct 2005
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2)
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.30/2.6.11.5 - BlueTooth 'bluez_sock_create' Local Privilege Escalation
CVE-2005-0750locallinux19 oct 2005
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5
23RIESGO
abrir
Exploit-DBVexDay Proof
Xerver 4.17 Server - URI Null Character Cross-Site Scripting
CVE-2005-4774remotewindows19 oct 2005
Cross-site scripting (XSS) vulnerability in Xerver 4.17 allows remote attackers to inject arbitrary web script or HTML a
23RIESGO
abrir
Exploit-DBVexDay Proof
HP-UX 11.11 - lpd Remote Command Execution (Metasploit)
CVE-2005-3277remotehp-ux19 oct 2005
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metac
28RIESGO
abrir
Exploit-DBVexDay Proof
Xerver 4.17 - Forced Directory Listing
CVE-2005-3293remotewindows19 oct 2005
Xerver 4.17 allows remote attackers to (1) obtain source code of scripts via a request with a trailing "." (dot) or (2)
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'edit_table_props.php?bgcolor' Cross-Site Scripting
CVE-2005-3520webappsphp18 oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'new_upgrade_functions.php' Multiple Remote File Inclusions
CVE-2005-3519webappsphp18 oct 2005
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'mail.php?PEAR_PATH' Remote File Inclusion
CVE-2005-3519webappsphp18 oct 2005
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'Date.php?PEAR_PATH' Remote File Inclusion
CVE-2005-3519webappsphp18 oct 2005
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'Span.php?PEAR_PATH' Remote File Inclusion
CVE-2005-3519webappsphp18 oct 2005
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'Socket.php?PEAR_PATH' Remote File Inclusion
CVE-2005-3519webappsphp18 oct 2005
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting
CVE-2005-3520webappsphp18 oct 2005
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
MySource 2.14 - 'Request.php?PEAR_PATH' Remote File Inclusion
CVE-2005-3519webappsphp18 oct 2005
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir
anteriorpágina 648 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.