Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
82.202 exploits
Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4881—webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4884—webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GE Fanuc Real Time Information Portal 2.6 - 'writeFile()' API (Metasploit)
CVE-2008-0175—remotewindows01 nov 2008
Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote at
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
YourFreeWorld Short Url & Url Tracker - SQL Injection
CVE-2008-4885—webappsphp01 nov 2008
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpWebSite 0.9.3 - 'links.php' SQL Injection
CVE-2008-6266—webappsphp31 oct 2008
SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
CVE-2008-4896—webappsphp31 oct 2008
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tribiq CMS 5.0.10a (Windows) - Local File Inclusion
CVE-2008-4893—webappsphp31 oct 2008
Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dovecot 1.1.x - Invalid Message Address Parsing Denial of Service
CVE-2008-4907—doslinux30 oct 2008
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows
23RIESGO
abrir ↗
Metasploit100
DjVu DjVu_ActiveX_MSOffice.dll ActiveX ComponentBuffer Overflow
CVE-2008-4922—30 oct 2008
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera Web Browser 9.x - History Search and Links Panel Cross-Site Scripting
CVE-2008-4795—remotelinux30 oct 2008
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft DebugDiag 1.0 - 'CrashHangExt.dll' ActiveX Control Remote Denial of Service
CVE-2008-4800—doswindows30 oct 2008
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attack
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SonicWALL - Content Filtering Blocked Site Error Page Cross-Site Scripting
CVE-2008-4918—remotehardware30 oct 2008
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and
23RIESGO
abrir ↗
Metasploit300
PacketTrap TFTP Server 2.2.5459.0 DoS
CVE-2008-1311—29 oct 2008
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PacketTrap TFTPD 2.2.5459.0 - Remote Denial of Service
CVE-2008-1311—doswindows29 oct 2008
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KKE Info Media Kmita Gallery - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-5068—webappsphp29 oct 2008
Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Extrakt Framework 0.7 - 'index.php' Cross-Site Scripting
CVE-2008-6217—webappsphp29 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitra
23RIESGO
abrir ↗
Metasploit500
MS08-067 Microsoft Server Service Relative Path Stack Corruption
CVE-2008-4250CRITICALbajo ataque28 oct 2008
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
Metasploit400
TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability
CVE-2008-4779—28 oct 2008
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Elkagroup Image Gallery 1.0 - 'view.php' SQL Injection
CVE-2008-5037—webappsphp28 oct 2008
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
H&H Solutions WebSoccer 2.80 - 'id' SQL Injection
CVE-2008-5064—webappsphp28 oct 2008
SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke Nuke League Module - 'tid' Cross-Site Scripting
CVE-2008-5039—webappsphp28 oct 2008
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KKE Info Media Kmita Catalogue 2 - 'search.php' Cross-Site Scripting
CVE-2008-5067—webappsphp28 oct 2008
Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - ' ' Address Bar URI Spoofing
CVE-2008-4787—webappsphp27 oct 2008
Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Python 2.5.2 - 'Imageop' Module Argument Validation Buffer Overflow
CVE-2008-4864—dosunix27 oct 2008
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
bcoos 1.0.13 - 'click.php' SQL Injection
CVE-2007-6080—webappsphp27 oct 2008
SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMyAdmin 3.0.1 - 'pmd_pdf.php' Cross-Site Scripting
CVE-2008-4775—webappsphp27 oct 2008
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
All In One 1.4 Control Panel - 'cp_polls_results.php' SQL Injection
CVE-2008-4782—webappsphp27 oct 2008
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.22 - 'ftruncate()'/'open()' Local Privilege Escalation
CVE-2008-4210—locallinux27 oct 2008
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java Web Start 1.0/1.2 - Remote Command Execution
CVE-2008-4910—remotemultiple25 oct 2008
The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a f
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iPeGuestbook 1.7/2.0 - 'pg' Cross-Site Scripting
CVE-2008-4751—webappsphp24 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
← anteriorpágina 1395 / 2741siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.