Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
82.202 exploits
Exploit-DB✓ VexDay Proof
vicFTP 5.0 - 'LIST' Remote Denial of Service
CVE-2008-2031—doswindows24 oct 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RIESGO
abrir ↗
Metasploit300
Victory FTP Server 5.0 LIST DoS
CVE-2008-6829—24 oct 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RIESGO
abrir ↗
Metasploit300
Victory FTP Server 5.0 LIST DoS
CVE-2008-2031—24 oct 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera 9.50/9.61 historysearch - Command Execution (Metasploit)
CVE-2008-4696—remotemultiple23 oct 2008
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.ty' Local Buffer Overflow (SEH)
CVE-2008-4686—localwindows23 oct 2008
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UC Gateway Investment SiteEngine 5.0 - 'announcements.php' SQL Injection
CVE-2008-7267—webappsphp23 oct 2008
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Osprey 1.0a4.1 - 'ListRecords.php' Multiple Remote File Inclusions
CVE-2008-6807—webappsphp23 oct 2008
PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - 'liste' Cross-Site Scripting
CVE-2008-6174—webappsphp23 oct 2008
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
CVE-2008-6789—webappsphp23 oct 2008
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ClipShare Pro 4.0 - 'fullscreen.php' Cross-Site Scripting
CVE-2008-6173—webappsphp23 oct 2008
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitr
23RIESGO
abrir ↗
Metasploit600
Opera historysearch XSS
CVE-2008-4696—23 oct 2008
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.ty' Local Buffer Overflow (SEH)
CVE-2008-4654—localwindows23 oct 2008
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adam Wright HTMLTidy 0.5 - 'html-tidy-logic.php' Cross-Site Scripting
CVE-2008-4761—webappsphp23 oct 2008
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UC Gateway Investment SiteEngine 5.0 - 'api.php' Open Redirection
CVE-2008-7269—webappsphp23 oct 2008
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
CVE-2008-6788—webappsphp23 oct 2008
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗
Metasploit400
VideoLAN VLC TiVo Buffer Overflow
CVE-2008-4654—22 oct 2008
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_IPUBLISH.ALTER_HOTLOG_INTERNAL_CSOURCE
CVE-2008-3996—22 oct 2008
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RIESGO
abrir ↗
Metasploit300
Oracle DB SQL Injection via SYS.LT.MERGEWORKSPACE
CVE-2008-3983—22 oct 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir ↗
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE
CVE-2008-3995—22 oct 2008
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dizi Portali - 'diziler.asp' SQL Injection
CVE-2008-6803—webappsasp21 oct 2008
SQL injection vulnerability in diziler.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.TY' Local Stack Buffer Overflow
CVE-2008-4686—localwindows21 oct 2008
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Bahar Download Script 2.0 - 'aspkat.asp' SQL Injection
CVE-2008-6075—webappsasp21 oct 2008
SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPhotoGallery 0.92 - 'index.php' SQL Injection
CVE-2008-6802—webappsphp21 oct 2008
Multiple SQL injection vulnerabilities in index.php in phPhotoGallery 0.92 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.TY' Local Stack Buffer Overflow
CVE-2008-4654—localwindows21 oct 2008
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - '/admin/cms/images.php?orderby' SQL Injection
CVE-2008-4651—webappsphp20 oct 2008
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke Sarkilar Module - 'id' SQL Injection
CVE-2008-6779—webappsphp20 oct 2008
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - '/admin/cms/nav.php?nav_id' SQL Injection
CVE-2008-4651—webappsphp20 oct 2008
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivvo CMS 3.4 - Multiple Vulnerabilities
CVE-2006-4715—webappsphp19 oct 2008
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earl
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BitTorrent 6.0.3 - '.torrent' Local Stack Buffer Overflow
CVE-2008-4434—localwindows19 oct 2008
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivvo CMS 3.4 - Multiple Vulnerabilities
CVE-2006-4714—webappsphp19 oct 2008
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RIESGO
abrir ↗
← anteriorpágina 1396 / 2741siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.