Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 5.1 - Hit Highlighting Authentication Bypass
CVE-2007-2815—remotewindows31 may 2007
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Bochs 2.3 - Buffer Overflow (Denial of Service) (PoC)
CVE-2007-2894—doslinux31 may 2007
The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyBloggie 2.1.x - 'index.php' Multiple SQL Injections
CVE-2007-3003—webappsphp31 may 2007
Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP JackKnife 2.21 - '/(PHPJK) UserArea/Authenticate.php?sUName' Cross-Site Scripting
CVE-2007-3001—webappsphp31 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LeadTools Raster ISIS Object 'LTRIS14e.DLL 14.5.0.44' - Remote Buffer Overflow (PoC)
CVE-2007-2980—doswindows30 may 2007
Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 al
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Particle Gallery 1.0 - 'search.php' Cross-Site Scripting
CVE-2007-2962—webappsphp30 may 2007
Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Mac OSX < 2007-005 - 'vpnd' Local Privilege Escalation
CVE-2007-0753—localosx30 may 2007
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LeadTools Raster OCR Document Object Library - Memory Corruption
CVE-2007-2981—doswindows30 may 2007
Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F-Secure Policy Manager 7.00 - 'FSMSH.dll' Remote Denial of Service
CVE-2007-2964—doswindows30 may 2007
The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial o
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Zenturi ProgramChecker - ActiveX File Download/Overwrite
CVE-2007-3076—remotewindows30 may 2007
A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UebiMiau 2.7.10 - '/demo/pop3/error.php' Multiple Full Path Disclosures
CVE-2007-3171—webappsphp29 may 2007
Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CPCommerce 1.1 - 'manufacturer.php' SQL Injection
CVE-2007-2959—webappsphp29 may 2007
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Metasploit600
Zenturi ProgramChecker ActiveX Control Arbitrary File Download
CVE-2007-2987—29 may 2007
Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UebiMiau 2.7.10 - '/demo/pop3/error.php?selected_theme' Cross-Site Scripting
CVE-2007-3170—webappsphp29 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
British TeleCommunications Consumer Webhelper 2.0.0.7 - Multiple Buffer Overflow Vulnerabilities
CVE-2007-2983—remotewindows29 may 2007
Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebco
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.9 - VPND Local Format String
CVE-2007-0753—localosx29 may 2007
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (1)
CVE-2007-2888—localwindows28 may 2007
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DGNews 2.1 - 'NewsID' SQL Injection
CVE-2007-0693—webappsphp28 may 2007
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mutt 1.4.2 - Mutt_Gecos_Name Function Local Buffer Overflow
CVE-2007-2683—locallinux28 may 2007
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DGNews 1.5.1/2.1 - 'news.php' SQL Injection
CVE-2007-0693—webappsphp28 may 2007
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DGNews 2.1 - 'footer.php' Cross-Site Scripting
CVE-2007-0694—webappsphp28 may 2007
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (2)
CVE-2007-2888—localwindows28 may 2007
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 2.0.58 mod_rewrite (Windows 2003) - Remote Overflow
CVE-2006-3747—remotewindows26 may 2007
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RIESGO
abrir ↗
Metasploit200
Mac OS X mDNSResponder UPnP Location Overflow
CVE-2007-2386—25 may 2007
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of servic
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pligg CMS 9.5 - Reset Forgotten Password Security Bypass
CVE-2007-5579—webappsphp25 may 2007
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BoastMachine 3.1 - 'index.php' Cross-Site Scripting
CVE-2007-2932—webappsphp25 may 2007
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - pppd Plugin Loading Privilege Escalation
CVE-2007-0752—localosx25 may 2007
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpPgAdmin 4.1.1 - 'Redirect.php' Cross-Site Scripting
CVE-2007-5728—webappsphp25 may 2007
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inje
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dart Communications PowerTCP - ZIP Compression Remote Buffer Overflow
CVE-2007-2856—remotewindows25 may 2007
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Interne
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNUTurk - 'Mods.php' Cross-Site Scripting
CVE-2007-2879—webappsphp25 may 2007
Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject a
23RIESGO
abrir ↗
← anteriorpágina 1467 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.