Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.252exploits catalogados
38.481CVEs con explotación pública
24.695probados en laboratorio
82.252 exploits
Exploit-DB✓ VexDay Proof
Google Chrome 0.2.149 - Malformed 'title' Tag Remote Denial of Service
CVE-2008-7061—dosmultiple02 sep 2008
The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 7.3.1 - 'Forum[]' Array SQL Injection
CVE-2008-6970—webappsphp02 sep 2008
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IDevSpot BizDirectory 2.04 - 'page' Cross-Site Scripting
CVE-2008-3941—webappsphp02 sep 2008
Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vTiger CRM 5.0.4 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-3101—webappsphp01 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Full PHP Emlak Script - 'landsee.php' SQL Injection
CVE-2008-3942—webappsphp29 ago 2008
SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenDB 1.0.6 - 'user_admin.php?user_id' Cross-Site Scripting
CVE-2008-3937MEDIUMwebappsphp28 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attack
33RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenDB 1.0.6 - 'listings.php?title' Cross-Site Scripting
CVE-2008-3937MEDIUMwebappsphp28 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attack
33RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenDB 1.0.6 - 'user_profile.php?redirect_url' Cross-Site Scripting
CVE-2008-3937MEDIUMwebappsphp28 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attack
33RIESGO
abrir ↗
Metasploit400
Ultra Shareware Office Control ActiveX HttpUpload Buffer Overflow
CVE-2008-3878—27 ago 2008
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat 8/9 - Directory Server Crafted Search Pattern Denial of Service
CVE-2008-2930—doslinux27 ago 2008
Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote atta
23RIESGO
abrir ↗
Metasploit600
AWStats Totals multisort Remote Command Execution
CVE-2008-3922—26 ago 2008
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences
50RIESGO
abrir ↗
Metasploit100
activePDF WebGrabber ActiveX Control Buffer Overflow
CVE-2008-20001HIGH26 ago 2008
activePDF WebGrabber ActiveX Control Buffer Overflow
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MatterDaddy Market 1.1 - 'login.php' Cross-Site Scripting
CVE-2008-4056—webappsphp26 ago 2008
Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Smart Survey 1.0 - 'surveyresults.asp' Cross-Site Scripting
CVE-2008-4051—webappsasp26 ago 2008
Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kyocera Mita Scanner File Utility 3.3.0.1 - File Transfer Directory Traversal
CVE-2008-7110—remotewindows26 ago 2008
Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dana IRC 1.4a - Remote Buffer Overflow
CVE-2008-2922—remotewindows25 ago 2008
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Belkin Wireless G Router / ADSL2 Modem - Authentication Bypass
CVE-2008-1245—remotehardware25 ago 2008
cgi-bin/setup_virtualserver.exe on the Belkin F5D7230-4 router with firmware 9.01.10 allows remote attackers to cause a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Bluemoon inc. PopnupBlog 3.30 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-4053—webappsphp25 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOO
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Belkin Wireless G Router / ADSL2 Modem - Authentication Bypass
CVE-2008-1242—remotehardware25 ago 2008
The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, whi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Belkin Wireless G Router / ADSL2 Modem - Authentication Bypass
CVE-2008-1244—remotehardware25 ago 2008
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows
23RIESGO
abrir ↗
Metasploit300
SoftArtisans XFile FileManager ActiveX Control Buffer Overflow
CVE-2007-1682—25 ago 2008
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
One-News - Multiple Input Validation Vulnerabilities
CVE-2008-7059—webappsphp23 ago 2008
SQL injection vulnerability in index.php in One-News Beta 2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ruby 1.9 - REXML Remote Denial of Service
CVE-2008-3790—doslinux23 ago 2008
The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
onenews Beta 2 - Cross-Site Scripting / HTML Injection / SQL Injection
CVE-2008-7059—webappsphp23 ago 2008
SQL injection vulnerability in index.php in One-News Beta 2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Media Services 'nskey.dll' 4.1 - ActiveX Control Remote Buffer Overflow
CVE-2008-5232—doswindows22 ago 2008
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PicturesPro Photo Cart 3.9 - Search Cross-Site Scripting
CVE-2008-3786—webappsphp22 ago 2008
Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Accellion File Transfer - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-3850—webappsphp22 ago 2008
Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fujitsu Web-Based Admin View 2.1.2 - Directory Traversal
CVE-2008-3776—remotelinux21 ago 2008
Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TimeTrex Time 2.2 and Attendance Module - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-4742—webappsphp21 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in interface/Login.php in TimeTrex 2.2.11 allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Scripts4Profit DXShopCart 4.30 - 'pid' SQL Injection
CVE-2008-4744—webappsphp21 ago 2008
SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
← anteriorpágina 1403 / 2742siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.