Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
82.322 exploits
Exploit-DB✓ VexDay Proof
Singapore 0.10.1 Modern Template - 'gallery' Cross-Site Scripting
CVE-2008-0400—webappsphp21 ene 2008
Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MegaBBS 1.5.14b - 'upload.asp' Cross-Site Scripting
CVE-2008-0436—webappsasp21 ene 2008
Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.4.10 - 'cpg1410_xek.php' SQL Injection
CVE-2008-0504—webappsphp21 ene 2008
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated admini
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alice Gate2 Plus Wi-Fi Router - Cross-Site Request Forgery
CVE-2008-7165—webappscgi21 ene 2008
Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mini File Host 1.2.1 - 'language' Local File Inclusion
CVE-2008-0357—webappsphp20 ene 2008
Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nucleus CMS 3.22 - 'action.php' Cross-Site Scripting
CVE-2008-0497—webappsphp20 ene 2008
Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0 - 'chrome://' URI JavaScript File Request Information Disclosure
CVE-2008-0418—remotelinux19 ene 2008
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BitDefender Products - Update Server HTTP Daemon Directory Traversal
CVE-2008-0396—remotewindows19 ene 2008
Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Sec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpAutoVideo 2.21 - 'index.php?cat' Cross-Site Scripting
CVE-2008-0432—webappsphp18 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject
23RIESGO
abrir ↗
Metasploit300
Winamp Ultravox Streaming Metadata (in_mp3.dll) Buffer Overflow
CVE-2008-0065—18 ene 2008
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbi
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
CVE-2008-0442—webappsphp18 ene 2008
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpAutoVideo 2.21 - 'sidebar.php?loadpage' Remote File Inclusion
CVE-2008-0433—webappsphp18 ene 2008
PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and ear
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CORE FORCE Firewall 0.95.167 and Registry Modules - Multiple Local Kernel Buffer Overflow Vulnerabilities
CVE-2008-0365—localwindows17 ene 2008
Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) an
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BitTorrent 6.0 / uTorrent 1.6/1.7 - Peers Window Remote Code Execution
CVE-2008-0364—remotewindows16 ene 2008
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyBB 1.2.10 - 'moderation.php' Multiple SQL Injections
CVE-2008-0383—webappsphp16 ene 2008
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
8E6 R3000 Internet Filter 2.0.5.33 - URI SecURIty Bypass
CVE-2008-0372—remotehardware16 ene 2008
8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restri
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Article Dashboard - '/admin/login.php' Multiple SQL Injections
CVE-2008-0286—webappsphp15 ene 2008
SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Peter's Math Anti-Spam 0.1.6 - Audio CAPTCHA Security Bypass
CVE-2008-7216—webappsphp15 ene 2008
Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files wi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
2WIRE Routers - Cross-Site Request Forgery
CVE-2007-4389—remotehardware15 ene 2008
Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
pMachine Pro 2.4.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0334—webappsphp14 ene 2008
Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fortinet Fortigate - CRLF Characters URL Filtering Bypass
CVE-2008-7161—remotehardware14 ene 2008
Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0265—remotehardware14 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Running Management 1.0.2 - 'index.php' Cross-Site Scripting
CVE-2008-0258—webappsphp13 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Moodle 1.8.3 - 'install.php' Cross-Site Scripting
CVE-2008-0123—webappsphp12 ene 2008
Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari 2.0.4 - KHTML WebKit Remote Denial of Service
CVE-2008-0298—dososx12 ene 2008
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a craf
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Members Area System 1.7 - 'view_func.php' Remote File Inclusion
CVE-2008-0289—webappsphp11 ene 2008
PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
CVE-2008-1709—localwindows11 ene 2008
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Qvod Player 2.1.5 - 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow
CVE-2008-4664—remotewindows11 ene 2008
Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ID-Commerce 2.0 - 'liste.php' SQL Injection
CVE-2008-0281—webappsphp10 ene 2008
SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Database 10 g - XML DB xdb.xdb_pitrig_pkg Package PITRIG_TRUNCATE Function Overflow
CVE-2008-0339—remotemultiple10 ene 2008
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unkn
28RIESGO
abrir ↗
← anteriorpágina 1436 / 2745siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.