Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Exploit-DB✓ VexDay Proof
contentserver 5.6.2929 - '/errors/transaction.asp?msg' Cross-Site Scripting
CVE-2007-3014—webappsasp13 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dating Gold 3.0.5 - 'footer.php?int_path' Remote File Inclusion
CVE-2007-3792—webappsphp13 jul 2007
Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
contentserver 5.6.2929 - '/errors/rights.asp?msg' Cross-Site Scripting
CVE-2007-3014—webappsasp13 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SkilMatch Systems JobLister3 - 'index.php' SQL Injection
CVE-2007-4359—webappsphp13 jul 2007
Multiple SQL injection vulnerabilities in SkilMatch Staffing Systems JobLister3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Inmostore 4.0 - 'index.php' SQL Injection
CVE-2007-3789—webappsphp12 jul 2007
SQL injection vulnerability in admin/index.php in Inmostore 4.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Helma 1.5.3 - Search Script Cross-Site Scripting
CVE-2007-3693—webappsphp12 jul 2007
Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Database - SQL Compiler Views Unauthorized Manipulation
CVE-2007-3855—localmultiple12 jul 2007
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remo
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SecureBlackbox 'PGPBBox.dll 5.1.0.112' - Arbitrary Data Write
CVE-2007-3785—remotewindows12 jul 2007
Absolute path traversal vulnerability in a certain ActiveX control in PGPBBox.dll in EldoS SecureBlackbox (sbb) 5.1.0.11
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec AntiVirus - 'symtdi.sys' Local Privilege Escalation
CVE-2007-3673—localwindows12 jul 2007
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Secur
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EnViVo!CMS - 'default.asp?ID' SQL Injection
CVE-2005-1413—webappsasp11 jul 2007
Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain p
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ClamAV / UnRAR - .RAR Handling Remote Null Pointer Dereference
CVE-2007-3725—remotelinux11 jul 2007
The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime 7.1.5 - Information Disclosure / Multiple Code Execution Vulnerabilities
CVE-2007-2394—remotemultiple11 jul 2007
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to ex
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer and Mozilla Firefox - URI Handler Command Injection
CVE-2007-3670—remotelinux10 jul 2007
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and cert
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.20.2 - 'IPv6_Getsockopt_Sticky' Memory Leak
CVE-2007-1000—locallinux10 jul 2007
The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java WebStart - JNLP Stack Buffer Overflow (PoC)
CVE-2007-3655—doswindows10 jul 2007
Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and e
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TippingPoint IPS - Unicode Character Detection Bypass
CVE-2007-3701—remotewindows10 jul 2007
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which m
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player 8.0.24 - '.SWF' File Handling Remote Code Execution
CVE-2007-3456—remotemultiple10 jul 2007
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ImgSvr 0.6 - 'Template' Local File Inclusion
CVE-2007-3714—webappslinux10 jul 2007
Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Program Checker - 'sasatl.dll 1.5.0.531' JavaScript HeapSpray
CVE-2007-3703—remotewindows10 jul 2007
Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Systeme de vote pour site Web 1.0 - Multiple Remote File Inclusions
CVE-2007-4384—webappsphp09 jul 2007
Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB
Sun Java Runtime Environment 1.6 - Web Start '.JNLP' File Stack Buffer Overflow
CVE-2007-3655—remotelinux09 jul 2007
Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and e
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Multiple Remote Command Execution Vulnerabilities
CVE-2007-3636—webappsphp09 jul 2007
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute ar
23RIESGO
abrir ↗
Metasploit0
SquirrelMail PGP Plugin Command Execution (SMTP)
CVE-2003-0990—09 jul 2007
The parseAddress code in (1) SquirrelMail 1.4.0 and (2) GPG Plugin 1.1 allows remote attackers to execute commands via s
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Tomcat Connector mod_jk - 'exec-shield' Remote Overflow
CVE-2007-0774—remotelinux08 jul 2007
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apach
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP DB 7.4 - WebTools Remote Overwrite (SEH)
CVE-2007-3614—remotewindows07 jul 2007
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NeoTracePro 3.25 - ActiveX 'TraceTarget()' Remote Buffer Overflow
CVE-2006-6707—remotewindows07 jul 2007
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Ex
50RIESGO
abrir ↗
Metasploit300
McAfee Visual Trace ActiveX Control Buffer Overflow
CVE-2006-6707—07 jul 2007
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Ex
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Levent Veysi Portal 1.0 - 'Oku.asp' SQL Injection
CVE-2007-3629—webappsasp07 jul 2007
SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft .Net Framework 2.0 - Multiple Null Byte Injection Vulnerabilities
CVE-2007-0042—remotewindows06 jul 2007
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and
45RIESGO
abrir ↗
Metasploit500
SAP DB 7.4 WebTools Buffer Overflow
CVE-2007-3614—05 jul 2007
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir ↗
← anteriorpágina 1461 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.