Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Exploit-DB✓ VexDay Proof
LeadTools MultiMedia 15 - 'Ltmm15.dll' ActiveX Control Stack Buffer Overflow
CVE-2007-2763—remotewindows17 may 2007
Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PsychoStats 2.3 - 'Server.php' Full Path Disclosure
CVE-2007-2780—webappsphp17 may 2007
PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Theme Redoable 1.2 - 'header.php?s' Cross-Site Scripting
CVE-2007-2757—webappsphp17 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PrecisionID Barcode ActiveX 1.9 - Remote Denial of Service
CVE-2007-2744—doswindows16 may 2007
Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java JDK 1.x - Multiple Vulnerabilities
CVE-2007-2788—remotelinux16 may 2007
Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.
28RIESGO
abrir ↗
Metasploit300
Symantec Norton Internet Security 2004 ActiveX Control Buffer Overflow
CVE-2007-1689—16 may 2007
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Sec
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Computer Associates BrightStor ARCserve Backup 11.5 - mediasvr caloggerd Denial of Service
CVE-2007-5332—doswindows16 may 2007
Multiple unspecified vulnerabilities in (1) mediasvr and (2) caloggerd in CA BrightStor ARCServe BackUp v9.01 through R1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vBulletin 3.6.6 - 'calendar.php' HTML Injection
CVE-2007-2908—webappsphp16 may 2007
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - '/view/search/?path' Cross-Site Scripting
CVE-2007-2732—webappsphp15 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Caucho Resin 3.1 - Encoded Space Request Full Path Disclosure
CVE-2007-2441—remotewindows15 may 2007
Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the sys
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XOOPS Module MyConference 1.0 - 'index.php' SQL Injection
CVE-2007-2737—webappsphp15 may 2007
SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Vista - Forged ARP packet Network Stack Denial of Service
CVE-2007-1531—doswindows15 may 2007
Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Caucho Resin 3.1 - '/web-inf' Traversal Arbitrary File Access
CVE-2007-2440—remotewindows15 may 2007
Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DeWizardX - 'DEWizardAX.ocx' Arbitrary File Overwrite
CVE-2007-2725—remotewindows15 may 2007
The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary fil
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 Email - 'FormMail.php' Input Validation
CVE-2007-1898—webappsphp15 may 2007
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTING
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - view/supplynews Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-2732—webappsphp15 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Clever Database Comparer ActiveX 2.2 - Remote Buffer Overflow (PoC)
CVE-2007-2648—doswindows14 may 2007
Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers
23RIESGO
abrir ↗
Metasploit200
Samba lsa_io_trans_names Heap Overflow
CVE-2007-2446—14 may 2007
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 3.0.21 < 3.0.24 - LSA trans names Heap Overflow (Metasploit)
CVE-2007-2446—remotelinux14 may 2007
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir ↗
Metasploit400
Samba lsa_io_trans_names Heap Overflow
CVE-2007-2446—14 may 2007
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir ↗
Metasploit200
TinyIdentD 2.2 Stack Buffer Overflow
CVE-2007-2711—14 may 2007
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RIESGO
abrir ↗
Metasploit200
Samba lsa_io_trans_names Heap Overflow
CVE-2007-2446—14 may 2007
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SonicBB 1.0 - 'search.php' Cross-Site Scripting
CVE-2007-1903—webappsphp14 may 2007
Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SonicBB 1.0 - Multiple SQL Injections
CVE-2007-1902—webappsphp14 may 2007
Multiple SQL injection vulnerabilities in SonicBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗
Metasploit600
Samba "username map script" Command Execution
CVE-2007-2447—14 may 2007
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
webdesproxy 0.0.1 - 'exec-shield' GET Remote Code Execution
CVE-2007-2668—remotelinux14 may 2007
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involvin
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
CVE-2007-2710—webappsphp14 may 2007
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Akismet 2.1.3 - Cross-Site Scripting
CVE-2007-2714—webappsphp14 may 2007
Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EQdkp 1.3.1 - Cross-Site Scripting
CVE-2007-2716—webappsphp12 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP FirstPost 0.1 - 'block.php?Include' Remote File Inclusion
CVE-2005-2412—webappsphp12 may 2007
PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗
← anteriorpágina 1469 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.