Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
82.745 exploits
Exploit-DB✓ VexDay Proof
LoveCMS 1.4 - 'id' Cross-Site Scripting
CVE-2007-1151—webappsphp22 feb 2007
Cross-site scripting (XSS) vulnerability in LoveCMS 1.4 allows remote attackers to inject arbitrary web script or HTML v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle 10g - KUPV$FT.ATTACH_JOB Grant/Revoke dba Permission
CVE-2006-0586—remotemultiple22 feb 2007
Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pheap 1.x/2.0 - 'edit.php' Directory Traversal
CVE-2007-1140—webappsphp22 feb 2007
Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pyrophobia 2.1.3.1 - Cross-Site Scripting
CVE-2007-1159—webappsphp22 feb 2007
Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle 10g - KUPW$WORKER.MAIN Grant/Revoke dba Permission
CVE-2006-3698—remotemultiple22 feb 2007
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Plantilla - 'list_main_pages.php?nfolder' Traversal Arbitrary File Access
CVE-2007-1138—webappsphp22 feb 2007
Absolute path traversal vulnerability in list_main_pages.php in Cromosoft Simple Plantilla PHP (SPP) allows remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - ReadDirectoryChangesW Information Disclosure
CVE-2007-0843—localwindows22 feb 2007
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions
23RIESGO
abrir ↗
Metasploit300
Wireshark chunked_encoding_dissector Function DOS
CVE-2007-3389—22 feb 2007
Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CedStat 1.31 - 'index.php' Cross-Site Scripting
CVE-2007-1020—webappsphp21 feb 2007
Cross-site scripting (XSS) vulnerability in index.php in CedStat 1.31 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Magic News Plus 1.0.2 - 'news.php?&link_parameters' Cross-Site Scripting
CVE-2007-1142—webappsphp21 feb 2007
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Magic News Plus 1.0.2 - 'n_layouts.php?link_parameters' Cross-Site Scripting
CVE-2007-1142—webappsphp21 feb 2007
Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Desktop - Cross-Site Scripting
CVE-2007-1085—webappscgi21 feb 2007
Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inje
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpTrafficA 1.4.1 - 'plotStat.php?File' Traversal Local File Inclusion
CVE-2007-1076—webappsphp21 feb 2007
Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to inclu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpTrafficA 1.4.1 - 'banref.php?lang' Traversal Local File Inclusion
CVE-2007-1076—webappsphp21 feb 2007
Multiple directory traversal vulnerabilities in phpTrafficA 1.4.1, and possibly earlier, allow remote attackers to inclu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Magic News Plus 1.0.2 - 'preview.php?PHP_script_path' Remote File Inclusion
CVE-2007-1141—webappsphp21 feb 2007
PHP remote file inclusion vulnerability in preview.php in Magic News Plus 1.0.2 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - Local File Access
CVE-2007-3406—remotewindows20 feb 2007
Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attacke
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeSentinel 2.5.05 - 'nukesentinel.php' File Disclosure
CVE-2007-1493—webappsphp20 feb 2007
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, whic
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AbleDesign MyCalendar 2.20.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-1050—webappsphp20 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.0.1 - 'location.hostname' Cross-Domain
CVE-2007-0981—remotewindows20 feb 2007
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remo
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Design4Online - 'Userpages2 Page.asp' SQL Injection
CVE-2007-1077—webappsasp20 feb 2007
SQL injection vulnerability in page.asp in Design4Online UserPages2 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NukeSentinel 2.5.05 - 'nsbypass.php' Blind SQL Injection
CVE-2007-5125—webappsphp20 feb 2007
20RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke 8.0 Final - 'INSERT' SQL Injection
CVE-2007-1061—webappsphp20 feb 2007
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP-Nuke 8.0 Final - 'INSERT' Blind SQL Injection (MySQL)
CVE-2007-1061—webappsphp20 feb 2007
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - ImageIO GIF Image Integer Overflow
CVE-2007-1071—dososx20 feb 2007
Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a d
28RIESGO
abrir ↗
Metasploit400
Trend Micro ServerProtect 5.58 Buffer Overflow
CVE-2007-1070—20 feb 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance F
60RIESGO
abrir ↗
Metasploit600
JBoss DeploymentFileRepository WAR Deployment (via JMXInvokerServlet)
CVE-2007-1036—20 feb 2007
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RIESGO
abrir ↗
Metasploit600
JBoss JMX Console Deployer Upload and Execute
CVE-2007-1036—20 feb 2007
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RIESGO
abrir ↗
Metasploit600
JBoss JMX Console Deployer Upload and Execute
CVE-2010-0738LOWbajo ataqueransomware20 feb 2007
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
95RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Spyce 2.1.3 - 'docs/examples/handlervalidate.spy?x' Cross-Site Scripting
CVE-2008-0980—webappsphp19 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
News File Grabber 4.1.0.1 - Subject Line Stack Buffer Overflow (2)
CVE-2007-1037—doswindows19 feb 2007
Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code v
23RIESGO
abrir ↗
← anteriorpágina 1492 / 2759siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.