Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Exploit-DB✓ VexDay Proof
PHP PEAR 1.5.3 - INSTALL-AS Attribute Arbitrary File Overwrite
CVE-2007-2519—remotelinux07 may 2007
Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to ov
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trend Micro ServerProtect 5.58 - 'SpntSvc.exe' Remote Stack Buffer Overflow
CVE-2007-2508—remotewindows07 may 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OTRS 2.0.4 - index.pl Cross-Site Scripting
CVE-2007-2524—webappscgi07 may 2007
Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FipsCMS 2.1 - 'pid' SQL Injection
CVE-2007-2561—webappsasp07 may 2007
SQL injection vulnerability in index.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SunShop Shopping Cart 4.0 - 'index.php' Multiple SQL Injections
CVE-2007-2549—webappsphp07 may 2007
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attackers to execute
23RIESGO
abrir ↗
Metasploit300
Solaris srsexec Arbitrary File Reader
CVE-2007-2617—07 may 2007
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file per
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Versalsoft HTTP File Uploader - ActiveX 6.36 AddFile Remote Denial of Service
CVE-2007-2563—doswindows07 may 2007
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remot
23RIESGO
abrir ↗
Metasploit400
Trend Micro ServerProtect 5.58 EarthAgent.EXE Buffer Overflow
CVE-2007-2508—07 may 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RIESGO
abrir ↗
Metasploit400
Trend Micro ServerProtect 5.58 CreateBinding() Buffer Overflow
CVE-2007-2508—07 may 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ELinks Relative 0.10.6/011.1 - Path Arbitrary Code Execution
CVE-2007-2027—locallinux07 may 2007
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SunShop Shopping Cart 4.0 - 'index.php?l' Cross-Site Scripting
CVE-2007-2547—webappsphp07 may 2007
Cross-site scripting (XSS) vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 allows remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Zoo 2.10 - .ZOO Compression Algorithm Remote Denial of Service
CVE-2007-2536—doswindows04 may 2007
PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Net Portal Dynamic System (NPDS) 5.10 - Remote Code Execution (2)
CVE-2007-2537—webappsphp04 may 2007
Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to exec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SharePoint Server 3.0 - Cross-Site Scripting
CVE-2007-2581—remotewindows04 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple 2.0.4 - Safari Local Cross-Site Scripting
CVE-2007-2580—localosx04 may 2007
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZOO - '.ZOO' Decompression Infinite Loop Denial of Service (PoC)
CVE-2007-1669—dosmultiple04 may 2007
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virus
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Office Viewer OCX 3.2.0.5 - Multiple Denial of Service Vulnerabilities
CVE-2007-2588—doswindows04 may 2007
Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx 3.8.5.0' Remote Stack Overflow
CVE-2007-0976—remotewindows04 may 2007
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Word Viewer OCX 3.2 - Remote Denial of Service
CVE-2007-2496—doswindows03 may 2007
The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Exp
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pre News Manager 1.0 - SQL Injection
CVE-2006-2763—webappsphp03 may 2007
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPSecurityAdmin 4.0.2 - 'Logout.php' Remote File Inclusion
CVE-2007-2628—webappsphp03 may 2007
PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityA
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Progress WebSpeed 3.0/3.1 - Denial of Service
CVE-2007-2506—doswindows02 may 2007
WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ObieWebsite Mini Web Shop 2 - 'order_form.php?PATH_INFO' Cross-Site Scripting
CVE-2007-2532—webappsphp02 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
3proxy 0.5.3g - exec-shield 'proxy.c logurl()' Remote Overflow
CVE-2007-2031—remotelinux02 may 2007
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Atomix MP3 - '.MP3' File Buffer Overflow
CVE-2007-2487—doswindows02 may 2007
Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CMS Made Simple 1.0.5 - 'Stylesheet.php' SQL Injection
CVE-2007-2473—webappsphp02 may 2007
SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗
Metasploit400
IBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow
CVE-2007-1868—02 may 2007
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ObieWebsite Mini Web Shop 2 - 'Sendmail.php?PATH_INFO' Cross-Site Scripting
CVE-2007-2532—webappsphp02 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.0.3 - Href Denial of Service
CVE-2007-2671—doswindows01 may 2007
Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
X.Org X Window System Xserver 1.3 - XRender Extension Divide by Zero Denial of Service
CVE-2007-2437—doslinux01 may 2007
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remo
23RIESGO
abrir ↗
← anteriorpágina 1472 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.