Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
Exploit-DB✓ VexDay Proof
JLMForo System - 'Buscado.php' Cross-Site Scripting
CVE-2007-5954MEDIUMwebappsphp05 nov 2007
Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary w
33RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - 'categories.php' Local File Inclusion
CVE-2007-2304—webappsphp03 nov 2007
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Helpdesk 0.6.16 - 'index.php' Local File Inclusion
CVE-2007-5915—webappsphp03 nov 2007
Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
CVE-2008-5010—dosmultiple02 nov 2007
in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU Emacs 22.1 - Local Variable Handling Code Execution
CVE-2007-5795—remotelinux02 nov 2007
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly s
23RIESGO
abrir ↗
Metasploit300
WinZip FileView (WZFILEVIEW.FileViewCtrl.61) ActiveX Buffer Overflow
CVE-2006-5198—02 nov 2007
The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before buil
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Synergiser 1.2 RC1 - Local File Inclusion / Full Path Disclosure
CVE-2007-5802—webappsphp02 nov 2007
Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Helios Calendar 1.1/1.2 - 'admin/index.php' Cross-Site Scripting
CVE-2007-5952—webappsphp02 nov 2007
Cross-site scripting (XSS) vulnerability in admin/index.php in Helios Calendar 1.2.1 Beta allows remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SonicWALL SSL VPN 1.3 3 WebCacheCleaner - ActiveX FileDelete Method Traversal Arbitrary File Deletion
CVE-2007-5815—remotewindows01 nov 2007
Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CONTENTCustomizer 3.1 - 'Dialog.php' Information Disclosure
CVE-2007-5816—webappsphp01 nov 2007
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by maki
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Synergiser 1.2 - 'index.php' Local File Inclusion
CVE-2007-5802—webappsphp01 nov 2007
Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote att
23RIESGO
abrir ↗
Metasploit300
SonicWall SSL-VPN NetExtender ActiveX Control Buffer Overflow
CVE-2007-5603—01 nov 2007
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RIESGO
abrir ↗
Metasploit300
Macrovision InstallShield Update Service Buffer Overflow
CVE-2007-5660—31 oct 2007
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Perdition 1.17 - IMAPD __STR_VWRITE Remote Format String
CVE-2007-5740—doslinux31 oct 2007
The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attack
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yarssr 0.2.2 - GUI.PM Remote Code Injection
CVE-2007-5837—remotelinux31 oct 2007
GUI.pm in yarssr 0.2.2, when Gnome default URL handling is disabled, allows remote attackers to execute arbitrary comman
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-AGTC Membership System 1.1a - Remote Add Admin
CVE-2007-5752—webappsphp30 oct 2007
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GlobalLink 2.7.0.8 - ConnectAndEnterRoom ActiveX Control Stack Buffer Overflow
CVE-2007-5722—remotewindows29 oct 2007
Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgam
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Saxon 5.4 - 'Example.php' SQL Injection
CVE-2007-4863—webappsphp29 oct 2007
SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Core 2.3 - 'Edit-Post-Rows.php' Cross-Site Scripting
CVE-2007-5710—webappsphp29 oct 2007
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Smart-Shop - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5725—webappsphp29 oct 2007
Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Omnistar Live - 'KB.php' Cross-Site Scripting
CVE-2007-5724—webappsphp29 oct 2007
Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Saxon 5.4 - 'Menu.php' Cross-Site Scripting
CVE-2007-4862—webappsphp29 oct 2007
Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Blue Coat ProxySG Management Console - URI Handler Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-5796—remotemultiple29 oct 2007
Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5
23RIESGO
abrir ↗
Metasploit300
GOM Player ActiveX Control Buffer Overflow
CVE-2007-5779—27 oct 2007
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Playe
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager 5.3 - Express CAD Service Buffer Overflow
CVE-2007-4880—remotewindows27 oct 2007
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CA BrightStor HSM r11.5 - Remote Stack Overflow / Denial of Service
CVE-2007-5082—doswindows27 oct 2007
Multiple stack-based buffer overflows in Computer Associates (CA) BrightStor Hierarchical Storage Manager (HSM) before r
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aleris Web Publishing Server 3.0 - 'Page.asp' SQL Injection
CVE-2007-6032—webappsasp25 oct 2007
SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TikiWiki 1.9.8.1 - Local File Inclusion
CVE-2007-5684—webappsphp25 oct 2007
Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multi-Forums - 'Directory.php' Multiple SQL Injections
CVE-2007-5688—webappsphp25 oct 2007
Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Shttp 0.0.x - Directory Traversal
CVE-2007-5685—remotelinux25 oct 2007
The safe_path function in shttp before 0.0.5 allows remote attackers to conduct directory traversal attacks and read fil
23RIESGO
abrir ↗
← anteriorpágina 1447 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.