Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
CVE-2006-2802doslinux
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RIESGO
abrir
ReferênciaVexDay Proof
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
CVE-2006-2834webappsphp
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2845webappsphp
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
CVE-2006-2848webappsasp
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
23RIESGO
abrir
ReferênciaVexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
CVE-2006-3162webappsphp
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
The Bible Portal Project 2.12 - 'destination' File Inclusion
CVE-2006-3177webappsphp
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
BlueShoes Framework 4.6 - Remote File Inclusion
CVE-2006-2864webappsphp
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrar
28RIESGO
abrir
ReferênciaVexDay Proof
empris r20020923 - 'phormationdir' Remote File Inclusion
CVE-2006-2962webappsphp
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923
23RIESGO
abrir
ReferênciaVexDay Proof
Enterprise Payroll Systems 1.1 - 'footer' Remote File Inclusion
CVE-2006-2982webappsphp
Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier all
23RIESGO
abrir
ReferênciaVexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
CVE-2006-2996webappsphp
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
CVE-2006-2998webappsphp
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Enthrallweb ePhotos 1.0 - 'subLevel2.asp' SQL Injection
CVE-2006-3027webappsasp
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
CVE-2006-3192webappsphp
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RIESGO
abrir
ReferênciaVexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
CVE-2006-3572webappsphp
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Winlpd 1.2 Build 1076 - Remote Buffer Overflow
CVE-2006-3670remotewindows
Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a requ
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (1)
CVE-2006-3730HIGHremotewindows
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_videodb 0.3en - Remote File Inclusion
CVE-2006-3736webappsphp
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Sitemap 2.0.0 - Remote File Inclusion
CVE-2006-3749webappsphp
PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS,
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_hashcash 1.2.1 - Remote File Inclusion
CVE-2006-3750webappsphp
PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
FlushCMS 1.0.0-pre2 - 'class.rich.php' Remote File Inclusion
CVE-2006-3754webappsphp
PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier a
23RIESGO
abrir
ReferênciaVexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
CVE-2006-3771webappsphp
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MoSpray 18RC1 - Remote File Inclusion
CVE-2006-3847webappsphp
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php
23RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.4 - 'old_prefix' Blind SQL Injection
CVE-2006-3851webappsphp
SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component User Home Pages 0.5 - Remote File Inclusion
CVE-2006-3995webappsphp
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RIESGO
abrir
ReferênciaVexDay Proof
Kayako eSupport 2.3.1 - 'subd' Remote File Inclusion
CVE-2006-4011webappsphp
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when regis
23RIESGO
abrir
ReferênciaVexDay Proof
MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections
CVE-2006-4042webappsphp
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
CVE-2006-4045webappsphp
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Open Cubic Player 2.6.0pre6/0.1.10_rc5 - Multiple Local Buffer Overflows
CVE-2006-4046localwindows
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier
28RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.WMF' CreateBrushIndirect Denial of Service
CVE-2006-4071doswindows
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP,
28RIESGO
abrir
anteriorpágina 179 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.