Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Tribiq CMS 5.0.10a (Windows) - Local File Inclusion
CVE-2008-4893webappsphp31 oct 2008
Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS
23RIESGO
abrir
Exploit-DBVexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
CVE-2008-4896webappsphp31 oct 2008
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Opera Web Browser 9.x - History Search and Links Panel Cross-Site Scripting
CVE-2008-4795remotelinux30 oct 2008
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
SonicWALL - Content Filtering Blocked Site Error Page Cross-Site Scripting
CVE-2008-4918remotehardware30 oct 2008
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DebugDiag 1.0 - 'CrashHangExt.dll' ActiveX Control Remote Denial of Service
CVE-2008-4800doswindows30 oct 2008
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attack
28RIESGO
abrir
Exploit-DBVexDay Proof
Dovecot 1.1.x - Invalid Message Address Parsing Denial of Service
CVE-2008-4907doslinux30 oct 2008
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows
23RIESGO
abrir
Exploit-DBVexDay Proof
PacketTrap TFTPD 2.2.5459.0 - Remote Denial of Service
CVE-2008-1311doswindows29 oct 2008
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RIESGO
abrir
Exploit-DBVexDay Proof
Extrakt Framework 0.7 - 'index.php' Cross-Site Scripting
CVE-2008-6217webappsphp29 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
KKE Info Media Kmita Gallery - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-5068webappsphp29 oct 2008
Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Nuke League Module - 'tid' Cross-Site Scripting
CVE-2008-5039webappsphp28 oct 2008
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Elkagroup Image Gallery 1.0 - 'view.php' SQL Injection
CVE-2008-5037webappsphp28 oct 2008
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
H&H Solutions WebSoccer 2.80 - 'id' SQL Injection
CVE-2008-5064webappsphp28 oct 2008
SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
KKE Info Media Kmita Catalogue 2 - 'search.php' Cross-Site Scripting
CVE-2008-5067webappsphp28 oct 2008
Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.22 - 'ftruncate()'/'open()' Local Privilege Escalation
CVE-2008-4210locallinux27 oct 2008
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi
23RIESGO
abrir
Exploit-DBVexDay Proof
All In One 1.4 Control Panel - 'cp_polls_results.php' SQL Injection
CVE-2008-4782webappsphp27 oct 2008
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - '&NBSP;' Address Bar URI Spoofing
CVE-2008-4787webappsphp27 oct 2008
Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a
28RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 3.0.1 - 'pmd_pdf.php' Cross-Site Scripting
CVE-2008-4775webappsphp27 oct 2008
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.
23RIESGO
abrir
Exploit-DBVexDay Proof
bcoos 1.0.13 - 'click.php' SQL Injection
CVE-2007-6080webappsphp27 oct 2008
SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Python 2.5.2 - 'Imageop' Module Argument Validation Buffer Overflow
CVE-2008-4864dosunix27 oct 2008
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta
28RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java Web Start 1.0/1.2 - Remote Command Execution
CVE-2008-4910remotemultiple25 oct 2008
The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a f
28RIESGO
abrir
Exploit-DBVexDay Proof
vicFTP 5.0 - 'LIST' Remote Denial of Service
CVE-2008-2031doswindows24 oct 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RIESGO
abrir
Exploit-DBVexDay Proof
iPeGuestbook 1.7/2.0 - 'pg' Cross-Site Scripting
CVE-2008-4751webappsphp24 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
ClipShare Pro 4.0 - 'fullscreen.php' Cross-Site Scripting
CVE-2008-6173webappsphp23 oct 2008
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Jetbox CMS 2.1 - 'liste' Cross-Site Scripting
CVE-2008-6174webappsphp23 oct 2008
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
UC Gateway Investment SiteEngine 5.0 - 'announcements.php' SQL Injection
CVE-2008-7267webappsphp23 oct 2008
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.ty' Local Buffer Overflow (SEH)
CVE-2008-4686localwindows23 oct 2008
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably
23RIESGO
abrir
Exploit-DBVexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
CVE-2008-6789webappsphp23 oct 2008
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
CVE-2008-6788webappsphp23 oct 2008
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Adam Wright HTMLTidy 0.5 - 'html-tidy-logic.php' Cross-Site Scripting
CVE-2008-4761webappsphp23 oct 2008
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.
23RIESGO
abrir
Exploit-DBVexDay Proof
UC Gateway Investment SiteEngine 5.0 - 'api.php' Open Redirection
CVE-2008-7269webappsphp23 oct 2008
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RIESGO
abrir
anteriorpágina 287 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.