Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.451exploits catalogados
38.590CVEs con explotación pública
24.695probados en laboratorio
82.451 exploits
Exploit-DB✓ VexDay Proof
X.Org X Window System Xserver 1.3 - XRender Extension Divide by Zero Denial of Service
CVE-2007-2437—doslinux01 may 2007
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
3proxy 0.5.3g (Windows x86) - 'proxy.c logurl()' Remote Buffer Overflow
CVE-2007-2031—remotewindows_x8630 abr 2007
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Aventail Connect 4.1.2.13 - Hostname Remote Buffer Overflow
CVE-2007-2434—doswindows30 abr 2007
Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (applicat
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
3proxy 0.5.3g (Linux) - 'proxy.c logurl()' Remote Buffer Overflow
CVE-2007-2031—remotelinux30 abr 2007
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Gazi Download Portal - 'Down_Indir.asp' SQL Injection
CVE-2007-2810—webappsasp30 abr 2007
SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
E-Annu - 'home.php' SQL Injection
CVE-2007-2416—webappsphp30 abr 2007
SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a pa
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fenice Oms server 1.10 - exec-shield Remote Buffer Overflow
CVE-2006-2022—remotelinux29 abr 2007
Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache AXIS 1.0 - Non-Existent WSDL Path Information Disclosure
CVE-2007-2353—remotemultiple27 abr 2007
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which re
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyDNS 1.1.0 - Remote Heap Overflow (PoC)
CVE-2007-2362—doslinux27 abr 2007
Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and poss
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ManageEngine Password Manager Pro Build 5401 - Database Remote Unauthorized Access
CVE-2007-2429—remotemultiple27 abr 2007
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injectin
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IPIX Image Well - ActiveX 'iPIX-ImageWell-ipix.dll' Remote Buffer Overflow
CVE-2007-1687—remotewindows27 abr 2007
Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll)
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - NCTAudioFile2.AudioFile ActiveX Remote Stack Overflow (2)
CVE-2007-0018—remotewindows27 abr 2007
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple prod
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2006-5758—remotewindows26 abr 2007
The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel stru
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EsForum 3.0 - 'forum.php?idsalon' SQL Injection
CVE-2007-2259—webappsphp26 abr 2007
SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1212—remotewindows26 abr 2007
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GIMP 2.2.14 - '.ras' SUNRAS Plugin Buffer Overflow
CVE-2007-2356—localwindows26 abr 2007
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MoinMoin 1.5.x - 'index.php' Cross-Site Scripting
CVE-2007-2423—webappsphp26 abr 2007
Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-0038—remotewindows26 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2006-5586—remotewindows26 abr 2007
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invali
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Burak Yilmaz Blog 1.0 - 'BRY.asp' SQL Injection
CVE-2007-2420—webappsasp26 abr 2007
SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1215—remotewindows26 abr 2007
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - NETLINK_FIB_LOOKUP Local Denial of Service
CVE-2007-1861—doslinux26 abr 2007
The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Doruk100Net - 'Info.php' Remote File Inclusion
CVE-2007-2288—webappsphp26 abr 2007
PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1211—remotewindows26 abr 2007
Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1213—remotewindows26 abr 2007
The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType f
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DynaTracker 1.5.1 - 'includes_handler.php?base_path' Remote File Inclusion
CVE-2007-2330—webappsphp25 abr 2007
PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HTMLEditBox 2.2 - 'config.php' Remote File Inclusion
CVE-2007-2327—webappsphp25 abr 2007
PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary P
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
plesk 8.1.1 - 'login.php3' Directory Traversal
CVE-2007-2268—webappsphp25 abr 2007
Multiple directory traversal vulnerabilities in SWsoft Plesk for Windows 7.6.1, 8.1.0, and 8.1.1 allow remote attackers
23RIESGO
abrir ↗
Metasploit200
CA BrightStor ArcServe Media Service Stack Buffer Overflow
CVE-2007-2139—25 abr 2007
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ahhp Portal - 'page.php' Multiple Remote File Inclusions
CVE-2007-2428—webappsphp25 abr 2007
Multiple PHP remote file inclusion vulnerabilities in page.php in Ahhp-Portal allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
← anteriorpágina 1473 / 2749siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.