Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
PHP-Nuke KutubiSitte Module - 'kid' SQL Injection
CVE-2008-1219webappsphp06 mar 2008
SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
Microworld eScan Server 9.0.742 - Directory Traversal
CVE-2008-1221remotewindows06 mar 2008
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Manag
23RIESGO
abrir
Exploit-DBVexDay Proof
Yap Blog 1.1 - 'index.php' Remote File Inclusion
CVE-2008-1370webappsphp06 mar 2008
PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Check Point VPN-1 UTM Edge NGX 7.0.48x - Login Page Cross-Site Scripting
CVE-2008-1208remotehardware06 mar 2008
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows r
23RIESGO
abrir
Exploit-DBVexDay Proof
Airspan ProST WiMAX Device - Web Interface Authentication Bypass
CVE-2008-1262remotehardware06 mar 2008
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication cr
23RIESGO
abrir
Exploit-DBVexDay Proof
Perforce Server 2007.3 - Multiple Remote Denial of Service Vulnerabilities
CVE-2008-1303doswindows05 mar 2008
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android Web Browser - '.GIF' File Heap Buffer Overflow
CVE-2008-0985dosandroid04 mar 2008
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows
23RIESGO
abrir
Exploit-DBVexDay Proof
BSD PPP 'pppx.conf' - Local Denial of Service
CVE-2008-1215dosbsd04 mar 2008
Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android Web Browser - '.BMP' File Integer Overflow
CVE-2008-0986dosandroid04 mar 2008
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier,
23RIESGO
abrir
Exploit-DBVexDay Proof
MG2 - 'list' Cross-Site Scripting
CVE-2008-1228webappsphp04 mar 2008
Cross-site scripting (XSS) vulnerability in admin.php in MG2 (formerly Minigal) allows remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
MiniWebsvr 0.0.9a - Remote Directory Traversal
CVE-2007-0919remotewindows03 mar 2008
Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
TorrentTrader 1.08 - 'msg' HTML Injection
CVE-2008-1173webappsphp03 mar 2008
Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to i
23RIESGO
abrir
Exploit-DBVexDay Proof
Borland VisiBroker Smart Agent 08.00.00.C1.03 - Multiple Remote Vulnerabilities
CVE-2008-7126doswindows03 mar 2008
Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to
28RIESGO
abrir
Exploit-DBVexDay Proof
KC Wiki 1.0 - '/simplest/wiki.php?page' Remote File Inclusion
CVE-2008-1170webappsphp03 mar 2008
Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
Exploit-DBVexDay Proof
KC Wiki 1.0 - '/minimal/wiki.php?page' Remote File Inclusion
CVE-2008-1170webappsphp03 mar 2008
Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Johannes Hass 'Gaestebuch 2.2 Module - 'id' SQL Injection
CVE-2008-1314webappsphp01 mar 2008
SQL injection vulnerability in the Johannes Hass gaestebuch 2.2 module for PHP-Nuke allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Simple PHP Scripts Gallery 0.x - 'index.php' Cross-Site Scripting
CVE-2008-4803webappsphp29 feb 2008
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
NetOffice Dwins 1.3 - Authentication Bypass / Arbitrary File Upload
CVE-2008-2044webappsphp29 feb 2008
includes/library.php in netOffice Dwins 1.3 p2 compares the demoSession variable to the 'true' string literal instead of
28RIESGO
abrir
Exploit-DBVexDay Proof
Centreon 1.4.2.3 - 'index.php' Local File Inclusion
CVE-2008-1178webappsphp29 feb 2008
Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to re
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPMyTourney 2 - '/tourney/index.php' Remote File Inclusion
CVE-2008-1128webappsphp29 feb 2008
PHP remote file inclusion vulnerability in tourney/index.php in phpMyTourney 2 allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
XRms 1.99.2 - CRM 'msg' Cross-Site Scripting
CVE-2008-1129webappsphp28 feb 2008
Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Flicks Software AuthentiX 6.3b1 - 'Username' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-1174webappsasp28 feb 2008
Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Juniper Networks Secure Access 2000 - 'rdremediate.cgi' Cross-Site Scripting
CVE-2008-1180remotehardware28 feb 2008
Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 b
23RIESGO
abrir
Exploit-DBVexDay Proof
Juniper Networks Secure Access 2000 Web - Root Full Path Disclosure
CVE-2008-1181webappscgi28 feb 2008
Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a d
23RIESGO
abrir
Exploit-DBVexDay Proof
Ghostscript 8.0.1/8.15 - 'zseticcspace()' Remote Buffer Overflow
CVE-2008-0411remotelinux27 feb 2008
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attacke
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan - Buffer Overflow (Denial of Service) (PoC)
CVE-2008-1365doswindows27 feb 2008
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patc
50RIESGO
abrir
Exploit-DBVexDay Proof
Nortel UNIStim IP Phone - Remote Ping Denial of Service
CVE-2008-4999doshardware26 feb 2008
Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping pa
23RIESGO
abrir
Exploit-DBVexDay Proof
Surgemail 3.0 - Real CGI executables Remote Buffer Overflow
CVE-2008-1054doswindows25 feb 2008
Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin Sur
23RIESGO
abrir
Exploit-DBVexDay Proof
Galore Simple Shop 3.1 - 'section' SQL Injection
CVE-2008-7033webappsphp25 feb 2008
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component for Joomla! allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
SurgeFTP 2.3a2 - 'Content-Length' Null Pointer Denial of Service
CVE-2008-1052doswindows25 feb 2008
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of servi
23RIESGO
abrir
anteriorpágina 317 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.