Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
Exploit-DB✓ VexDay Proof
SunOS 5.10 - Remote ICMP Kernel Crash
CVE-2007-0634—dossolaris10 ene 2008
Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ID-Commerce 2.0 - 'liste.php' SQL Injection
CVE-2008-0281—webappsphp10 ene 2008
SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Database 10 g - XML DB xdb.xdb_pitrig_pkg Package PITRIG_TRUNCATE Function Overflow
CVE-2008-0339—remotemultiple10 ene 2008
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unkn
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/user/main.jsp?activeControl' Cross-Site Scripting
CVE-2008-0239—webappsjsp09 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RIESGO
abrir ↗
Metasploit300
SAP MaxDB cons.exe Remote Command Injection
CVE-2008-0244—09 ene 2008
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xine-Lib 1.1.9 - 'rmff_dump_cont()' Remote Heap Buffer Overflow (PoC)
CVE-2008-0225—doslinux09 ene 2008
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows r
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/login.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0239—webappsjsp09 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injection
CVE-2008-0240—webappsjsp09 ene 2008
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Omegasoft Insel 7 - Authentication Bypass / User Enumeration
CVE-2008-1134—webappsphp09 ene 2008
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/account/findForSelect.jsp?resultsForm' Cross-Site Scripting
CVE-2008-0239—webappsjsp09 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RIESGO
abrir ↗
Metasploit200
XTACACSD report() Buffer Overflow
CVE-2008-7232—08 ene 2008
Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code v
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SysHotel On Line System - 'index.php' Local File Inclusion
CVE-2008-0184—webappsphp08 ene 2008
Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xtacacsd 4.1.2 - 'report()' Remote Buffer Overflow (Metasploit)
CVE-2008-7232—remotebsd08 ene 2008
Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code v
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IceWarp Mail Server 9.1.1 - '/admin/index.html' Cross-Site Scripting
CVE-2008-0218—webappsphp08 ene 2008
Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'view.php?s' Cross-Site Scripting
CVE-2008-0268—webappsphp07 ene 2008
Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'admin.php' Cross-Site Request Forgery
CVE-2008-0266—webappsphp07 ene 2008
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the ad
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'admin.php' Multiple SQL Injections
CVE-2008-0267—webappsphp07 ene 2008
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL comm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SynCE 0.92 - 'vdccm' Daemon Remote Command Injection
CVE-2008-1136—remotelinux07 ene 2008
The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
CVE-2007-5759—remotelinux07 ene 2008
20RIESGO
abrir ↗
Exploit-DB
Creative Ensoniq PCI ES1371 WDM Driver 5.1.3612 - Local Privilege Escalation
CVE-2008-7211—localwindows07 ene 2008
CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eTicket 1.5.5.2 - 'search.php' Multiple SQL Injections
CVE-2008-0267—webappsphp07 ene 2008
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL comm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Horde Web-Mail 3.x - 'go.php' Remote File Disclosure
CVE-2006-1260—webappsphp06 ene 2008
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parame
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetRisk 1.9.7 - Remote Password Change
CVE-2008-7155—webappsphp05 ene 2008
NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pragma Systems FortressSSH 5.0 - 'msvcrt.dll' Exception Handling Remote Denial of Service
CVE-2008-0132—dosmultiple04 ene 2008
Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message wind
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pragma TelnetServer 7.0.4.589 - NULL-Pointer Dereference Denial of Service
CVE-2008-0153—dosmultiple04 ene 2008
telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and res
28RIESGO
abrir ↗
Metasploit400
MySQL yaSSL SSL Hello Message Buffer Overflow
CVE-2008-0226—04 ene 2008
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RIESGO
abrir ↗
Metasploit200
MySQL yaSSL SSL Hello Message Buffer Overflow
CVE-2008-0226—04 ene 2008
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL 6.0 yaSSL 1.7.5 - Hello Message Buffer Overflow (Metasploit)
CVE-2008-0226—remotelinux04 ene 2008
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foxit WAC Server 2.0 Build 3503 - Denial of Service
CVE-2008-0151—dosmultiple04 ene 2008
Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PRO-Search 0.17 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0207—webappsphp03 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbi
23RIESGO
abrir ↗
← anteriorpágina 1439 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.