Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Exploit-DB✓ VexDay Proof
SAP DB 7.x Web Server - 'WAHTTP.exe' Multiple Buffer Overflow Vulnerabilities
CVE-2007-3614—remotewindows05 jul 2007
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GFax 0.7.6 - Temporary Files Local Arbitrary Command Execution
CVE-2007-2839—locallinux05 jul 2007
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Maia Mailguard 1.0.2 - 'login.php' Multiple Local File Inclusions
CVE-2007-3619—webappsphp05 jul 2007
Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbit
23RIESGO
abrir ↗
Metasploit300
EnjoySAP SAP GUI ActiveX Control Buffer Overflow
CVE-2007-3605—05 jul 2007
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP Message Server - 'Group' Remote Buffer Overflow
CVE-2007-3624—remotemultiple05 jul 2007
Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary
35RIESGO
abrir ↗
Metasploit500
SAP DB 7.4 WebTools Buffer Overflow
CVE-2007-3614—05 jul 2007
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetFlow Analyzer 5 - '/jspui/selectDevice.jsp?rtype' Cross-Site Scripting
CVE-2007-3593—webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetFlow Analyzer 5 - '/jspui/appConfig.jsp?task' Cross-Site Scripting
CVE-2007-3593—webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpManager 6/7 - reports/ReportViewAction.do Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3594—webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetFlow Analyzer 5 - '/jspui/applicationList.jsp?alpha' Cross-Site Scripting
CVE-2007-3593—webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetFlow Analyzer 5 - '/jspui/customReport.jsp?rtype' Cross-Site Scripting
CVE-2007-3593—webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpManager 6/7 - 'admin/ServiceConfiguration.do?Operation' Cross-Site Scripting
CVE-2007-3594—webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetFlow Analyzer 5 - 'netflow/jspui/index.jsp?view' Cross-Site Scripting
CVE-2007-3593—webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpManager 6/7 - '/admin/DeviceAssociation.do' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3594—webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpManager 6/7 - 'ping.do?name' Cross-Site Scripting
CVE-2007-3594—webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpManager 6/7 - 'traceRoute.do?name' Cross-Site Scripting
CVE-2007-3594—webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AXIS Camera Control (AxisCamControl.ocx 1.0.2.15) - Remote Buffer Overflow
CVE-2007-2239—remotewindows03 jul 2007
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ESRI ArcSDE 9.0 < 9.2sp1 - Remote Buffer Overflow
CVE-2007-1770—remotewindows03 jul 2007
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Serv
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fujitsu ServerView 4.50.8 - DBASCIIAccess Remote Command Execution
CVE-2007-3011—remotemultiple03 jul 2007
The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oliver - Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3569—webappscgi03 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Plume CMS 1.0.4 - 'rss.php?_PX_config[manager_path]' Remote File Inclusion
CVE-2006-3562—webappsphp03 jul 2007
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Plume CMS 1.0.4 - 'index.php?_PX_config[manager_path]' Remote File Inclusion
CVE-2006-3562—webappsphp03 jul 2007
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Helix Player 11.0.2 - Encoded URI Processing Buffer Overflow
CVE-2010-0416—remotelinux03 jul 2007
Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Liesbeth Base CMS - Information Disclosure
CVE-2007-3556—webappsphp02 jul 2007
Liesbeth base CMS stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Instant Support - Driver Check Remote Buffer Overflow (PoC)
CVE-2007-3554—doswindows02 jul 2007
Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check be
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPDirector 0.21 - 'videos.php?id' SQL Injection
CVE-2007-3529—webappsphp02 jul 2007
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPDirector 0.21 - 'videos.php?id' SQL Injection
CVE-2007-3530—webappsphp02 jul 2007
PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yoggie Pico and Pico Pro Backticks - Remote Code Execution
CVE-2007-3572—webappscgi02 jul 2007
Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro al
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Moodle 1.7.1 - 'index.php' Cross-Site Scripting
CVE-2007-3555—webappsphp02 jul 2007
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Claroline 1.8.3 - '$_SERVER['PHP_SELF']' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3517—webappsphp02 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
← anteriorpágina 1462 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.