Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
ZoneAlarm Security Suite 7.0 - AntiVirus Directory Path Buffer Overflow (PoC)
CVE-2008-7009doswindows11 sep 2008
Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users
23RIESGO
abrir
Exploit-DBVexDay Proof
Nooms 1.1 - 'search.php?q' Cross-Site Scripting
CVE-2008-4179webappsphp11 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script o
23RIESGO
abrir
Exploit-DBVexDay Proof
Autodealers CMS AutOnline - 'pageid' SQL Injection
CVE-2008-4074webappsphp11 sep 2008
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Horde Application Framework 3.2.1 - Forward Slash Insufficient Filtering Cross-Site Scripting
CVE-2008-3824webappsphp10 sep 2008
Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before
23RIESGO
abrir
Exploit-DBVexDay Proof
Libera CMS 1.12 - 'cookie' SQL Injection
CVE-2008-4701webappsphp10 sep 2008
SQL injection vulnerability in admin.php in Libera CMS 1.12, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Hot Links SQL-PHP - 'news.php' SQL Injection
CVE-2008-7120webappsphp10 sep 2008
SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Horde 3.2 - MIME Attachment Filename Insufficient Filtering Cross-Site Scripting
CVE-2008-3823webappsphp10 sep 2008
Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.6.1 - Admin Takeover (SQL Column Truncation)
CVE-2009-2762webappsphp10 sep 2008
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the
28RIESGO
abrir
Exploit-DBVexDay Proof
Alstrasoft Forum - 'catid' SQL Injection
CVE-2008-3954webappsphp09 sep 2008
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Bonjour for Windows 1.0.4 - mDNSResponder Null Pointer Dereference Denial of Service
CVE-2008-2326doswindows09 sep 2008
mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a de
23RIESGO
abrir
Exploit-DBVexDay Proof
eXtrovert software Thyme 1.3 - 'pick_users.php' SQL Injection
CVE-2008-4459webappsphp08 sep 2008
SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Image Acquisition Logger ActiveX Control Arbitrary File Overwrite (2)
CVE-2008-3957remotewindows08 sep 2008
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrar
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Organization Chart 2 - Remote Code Execution
CVE-2008-3956remotewindows08 sep 2008
orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (applicati
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Image Acquisition Logger ActiveX Control Arbitrary File Overwrite (1)
CVE-2008-3957remotewindows08 sep 2008
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrar
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.2.5 - Multiple functions 'safe_mode_exec_dir' / 'open_basedir' Restriction Bypass Vulnerabilities
CVE-2008-7002localphp08 sep 2008
PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might a
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DIR-100 1.12 - Security Bypass
CVE-2008-4133remotehardware08 sep 2008
The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with la
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.6.1 - SQL Column Truncation
CVE-2009-2762webappsphp07 sep 2008
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the
28RIESGO
abrir
Exploit-DBVexDay Proof
phpAdultSite CMS - 'results_per_page' Cross-Site Scripting
CVE-2008-6979webappsphp07 sep 2008
Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
E-PHP B2B Trading Marketplace Script - 'listings.php' SQL Injection
CVE-2008-4458webappsphp07 sep 2008
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Silentum LoginSys 1.0 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-6764webappsphp06 sep 2008
Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
WebCMS Portal Edition - 'id' Blind SQL Injection
CVE-2008-4186webappsphp05 sep 2008
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
EsFaq 2.0 - 'idcat' SQL Injection
CVE-2008-6016webappsphp05 sep 2008
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'company_name' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'title' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'campaign_title' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'file_id' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'case_title' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'last_name' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'starting' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - 'opportunity_title' Cross-Site Scripting
CVE-2008-3664webappsphp04 sep 2008
Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
anteriorpágina 292 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.