Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Metasploit400
Trend Micro OfficeScan Remote Stack Buffer Overflow
CVE-2008-1365—28 jun 2007
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patc
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Rapid Install Web Server - Secondary Login Page Cross-Site Scripting
CVE-2007-3553—remotemultiple28 jun 2007
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PC SOFT WinDEV 11 - '.WDP' File Parsing Stack Buffer Overflow
CVE-2007-3479—doswindows28 jun 2007
Stack-based buffer overflow in PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Conti FTP Server 1.0 - Large String Denial of Service
CVE-2007-3492—doswindows27 jun 2007
Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer/HelixPlayer - SMIL wallclock Stack Overflow (PoC)
CVE-2007-3410—doswindows27 jun 2007
Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPla
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linksys WAG54GS 1.0.6 (Wireless-G ADSL Gateway) - 'setup.cgi' Cross-Site Scripting
CVE-2007-3574—remotehardware27 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway wi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ETicket 1.5.5 - 'Open.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-2801—webappsphp27 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GD Graphics Library 2.0.34 - 'libgd' gdImageCreateXbm Function Unspecified Denial of Service
CVE-2007-3473—doslinux26 jun 2007
The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Key Focus Web Server 3.1 - Index.WKF Cross-Site Scripting
CVE-2007-3396—remotemultiple25 jun 2007
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to injec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Calendarix 0.7.20070307 - Multiple SQL Injections
CVE-2007-3183—webappsphp25 jun 2007
Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyNews 0.10 - AuthACC SQL Injection
CVE-2007-2520—webappsphp25 jun 2007
SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebCT 4.1.5 - Email and Discussion Board Messages HTML Injection
CVE-2008-1225—webappsphp25 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SHTTPD 1.38 - Filename Parse Error Information Disclosure
CVE-2007-3407—remotemultiple25 jun 2007
Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Calendarix 0.7.20070307 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3182—webappsphp25 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
6ALBlog - 'newsid' SQL Injection
CVE-2007-3450—webappsphp25 jun 2007
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the m
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LiteWEB Web Server 2.7 - Invalid Page Remote Denial of Service
CVE-2007-3398—doswindows25 jun 2007
LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent p
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari 3.0.x for Windows - 'Document.Location.Hash' Buffer Overflow
CVE-2007-4812—doswindows25 jun 2007
Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetClassifieds - SQL Injection / Cross-Site Scripting / Full Path
CVE-2005-3978—webappsphp22 jun 2007
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eNdonesia 8.4 - 'mod.php?viewarticle Action artid' SQL Injection
CVE-2007-3394—webappsphp22 jun 2007
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple WebCore - XMLHTTPRequest Cross-Site Scripting
CVE-2007-2401—remoteosx22 jun 2007
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eNdonesia 8.4 - 'banners.php?click Action bid' SQL Injection
CVE-2007-3394—webappsphp22 jun 2007
Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Metasploit300
RKD Software BarCodeAx.dll v4.9 ActiveX Remote Stack Buffer Overflow
CVE-2007-3435—22 jun 2007
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyServer 0.8.9 - Filename Parse Error Information Disclosure
CVE-2007-3365—remotemultiple21 jun 2007
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetClassifieds 1.9.7 - Multiple Input Validation Vulnerabilities
CVE-2007-3354—webappsphp21 jun 2007
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPAccounts 0.5 - 'index.php' Local File Inclusion
CVE-2007-3346—webappsphp21 jun 2007
Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local fil
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ingress Database Server 2.6 - Multiple Remote Vulnerabilities
CVE-2007-3334—doswindows21 jun 2007
Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe)
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BugHunter HTTP Server 1.6.2 - 'httpsv.exe' GET 404 Remote Denial of Service
CVE-2007-3340—doswindows21 jun 2007
BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Comersus Cart 7.0.7 - 'comersus_customerAuthenticateForm.asp' redirectUrl Cross-Site Scripting
CVE-2007-3324—webappsasp20 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Comersus Cart 7.0.7 - 'comersus_message.asp' redirectUrl Cross-Site Scripting
CVE-2007-3324—webappsasp20 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FuseTalk 4.0 - 'blog/include/common/comfinish.cfm?FTVAR_SCRIPTRUN' Cross-Site Scripting
CVE-2007-3339—webappsasp20 jun 2007
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, En
23RIESGO
abrir ↗
← anteriorpágina 1463 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.