Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
82.202 exploits
Exploit-DB✓ VexDay Proof
Konqueror 3.5.9 - 'color'/'bgcolor' Multiple Remote Crash Vulnerabilities
CVE-2008-4514—doslinux08 oct 2008
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MPlayer - '.AAC' File Handling Denial of Service
CVE-2008-4610—doslinux07 oct 2008
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demons
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yerba SACphp 6.3 - Multiple Vulnerabilities
CVE-2008-4486—webappsphp07 oct 2008
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MPlayer - '.OGM' File Handling Denial of Service
CVE-2008-4610—doslinux07 oct 2008
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demons
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.0.3 - Internet Shortcut Same Origin Policy Violation
CVE-2008-4582—remotemultiple07 oct 2008
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windo
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-5712—doslinux06 oct 2008
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Internet Download Manager 4.0.5 - File Parsing Buffer Overflow
CVE-2008-4508—remotewindows06 oct 2008
Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Web Explorer 0.99b - 'edit.php?File' Traversal Local File Inclusion
CVE-2008-4499—webappsphp06 oct 2008
Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Web Explorer 0.99b - 'main.php?refer' Traversal Local File Inclusion
CVE-2008-4499—webappsphp06 oct 2008
Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and
23RIESGO
abrir ↗
Metasploit300
iseemedia / Roxio / MGI Software LPViewer ActiveX Control Buffer Overflow
CVE-2008-4384—06 oct 2008
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VeriSign Kontiki Delivery Management System 5.0 - 'action' Cross-Site Scripting
CVE-2008-4393—webappsjava05 oct 2008
Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AmpJuke 0.7.5 - 'index.php' SQL Injection
CVE-2008-4525—webappsphp03 oct 2008
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Website Directory - 'index.php' Cross-Site Scripting
CVE-2008-4532—webappsphp03 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player 9/10 - SWF Version Null Pointer Dereference Denial of Service
CVE-2008-4546—doslinux02 oct 2008
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web serv
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
libxml2 - Denial of Service
CVE-2008-4409—dosunix02 oct 2008
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dep
23RIESGO
abrir ↗
Metasploit300
mIRC PRIVMSG Handling Stack Buffer Overflow
CVE-2008-4449—02 oct 2008
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel (Fedora 8/9) - 'utrace_control' Null Pointer Dereference Denial of Service
CVE-2008-3832—doslinux02 oct 2008
A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI (EMR_COLORMATCHTOTARGETW) (MS08-021)
CVE-2008-1083HIGHremotewindows02 oct 2008
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dreamcost HostAdmin 3.1 - 'index.php' Cross-Site Scripting
CVE-2008-6164—webappsphp02 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Celoxis - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-6094—webappsjava01 oct 2008
Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpScheduleIt 1.2.10 - 'reserve.php' Remote Code Execution
CVE-2008-6132—webappsphp01 oct 2008
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
A4Desk Event Calendar - 'eventid' SQL Injection
CVE-2008-6104—webappsphp01 oct 2008
SQL injection vulnerability in A4Desk PHP Event Calendar allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
H-Sphere WebShell 4.3.10 - 'actions.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-4447—webappsphp01 oct 2008
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WikyBlog 1.7.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-6097—webappsphp01 oct 2008
Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Metasploit600
phpScheduleIt PHP reserve.php start_date Parameter Arbitrary Code Injection
CVE-2008-6132—01 oct 2008
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion
CVE-2008-4454—webappsphp01 oct 2008
Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ADN Forum 1.0b - Blind SQL Injection
CVE-2006-0123—webappsphp01 oct 2008
Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpScheduleIt 1.2.10 - 'reserve.php' Remote Code Execution
CVE-2009-0820—webappsphp01 oct 2008
Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xen 3.3 - XenStore Domain Configuration Data Unsafe Storage
CVE-2008-4405—locallinux30 sep 2008
xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not proper
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL 5 - Command Line Client HTML Special Characters HTML Injection
CVE-2008-4456—remotelinux30 sep 2008
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions i
23RIESGO
abrir ↗
← anteriorpágina 1398 / 2741siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.