Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
Exploit-DB✓ VexDay Proof
Adobe Acrobat and Reader 8.1.1 - Multiple Arbitrary Code Execution / Security Vulnerabilities
CVE-2007-5659HIGHbajo ataquedoswindows06 feb 2008
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RIESGO
abrir ↗
Metasploit300
UltraVNC 1.0.2 Client (vncviewer.exe) Buffer Overflow
CVE-2008-0610—06 feb 2008
Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp
50RIESGO
abrir ↗
Metasploit400
WinComLPD Buffer Overflow
CVE-2008-5159—04 feb 2008
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earl
50RIESGO
abrir ↗
Metasploit400
SAP SAPLPD 6.28 Buffer Overflow
CVE-2008-0621—04 feb 2008
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Simple OS CMS 0.1c_beta - 'login.php' SQL Injection
CVE-2008-0650—webappsphp04 feb 2008
SQL injection vulnerability in login.php in Simple OS CMS 0.1c beta allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AstroSoft HelpDesk - '/operator/article/article_attachment.asp?Attach_Id' Cross-Site Scripting
CVE-2008-0605—webappsasp04 feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Codice CMS - 'login.php' SQL Injection
CVE-2008-0651—webappsphp04 feb 2008
SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MPlayer 1.0rc2 - 'demux_mov.c' Remote Code Execution
CVE-2008-0485—remotelinux04 feb 2008
Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CruxCMS 3.0 - 'search.php' Cross-Site Scripting
CVE-2008-0700—webappsphp04 feb 2008
Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Portail Web PHP 2.5.1 - 'login.php' Remote File Inclusion
CVE-2008-0645—webappsphp04 feb 2008
Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrar
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AstroSoft HelpDesk - '/operator/article/article_search_results.asp?txtSearch' Cross-Site Scripting
CVE-2008-0605—webappsasp04 feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Portail Web PHP 2.5.1 - 'item.php' Remote File Inclusion
CVE-2008-0645—webappsphp04 feb 2008
Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrar
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Titan FTP Server 6.05 build 550 - 'DELE' Remote Buffer Overflow (PoC)
CVE-2008-5281—doswindows04 feb 2008
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a lo
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WinComLPD Total 3.0.2.623 - Remote Buffer Overflow / Authentication Bypass
CVE-2008-5159—remotemultiple04 feb 2008
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earl
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Portail Web PHP 2.5.1 - 'conf-activation.php' Remote File Inclusion
CVE-2008-0645—webappsphp04 feb 2008
Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrar
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Portail Web PHP 2.5.1 - 'conf_modules.php' Remote File Inclusion
CVE-2008-0645—webappsphp04 feb 2008
Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrar
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DevTracker Module For bcoos 1.1.11 and E-xoops 1.0.8 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-7036—webappsphp04 feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Anon Proxy Server 0.100/0.102 - Remote Authentication Buffer Overflow
CVE-2008-0633—dosmultiple04 feb 2008
Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FaceBook PhotoUploader - 'ImageUploader4.ocx 4.5.57.0' Remote Buffer Overflow
CVE-2008-5711—remotewindows03 feb 2008
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
CVE-2008-0624—remotewindows03 feb 2008
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0623—remotewindows03 feb 2008
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
CVE-2008-0624—remotewindows03 feb 2008
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-0624—doswindows02 feb 2008
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ITechClassifieds - 'viewcat.php?CatID' SQL Injection
CVE-2008-0685—webappsphp02 feb 2008
SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ITechClassifieds - 'viewcat.php?CatID' Cross-Site Scripting
CVE-2008-0684—webappsphp02 feb 2008
Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin WP-Footnotes 2.2 - Multiple Remote Vulnerabilities
CVE-2008-0691—webappsphp02 feb 2008
Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for W
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Domain Trader 2.0 - 'catalog.php' Cross-Site Scripting
CVE-2008-0688—webappsphp02 feb 2008
Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Liferay Enterprise Portal 4.3.6 - User-Agent HTTP Header Cross-Site Scripting
CVE-2008-0178—webappsphp31 ene 2008
Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 al
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nilson's Blogger 0.11 - 'comments.php' Local File Inclusion
CVE-2008-0559—webappsphp31 ene 2008
Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbi
23RIESGO
abrir ↗
Metasploit300
Facebook Photo Uploader 4 ActiveX Control Buffer Overflow
CVE-2008-5711—31 ene 2008
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RIESGO
abrir ↗
← anteriorpágina 1434 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.