Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.051exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
AmpJuke 0.7 - 'index.php' Cross-Site Scripting
CVE-2008-0496webappsphp29 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in AmpJuke 0.7.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
SunGard Banner Student 7.3 - 'add1' Cross-Site Scripting
CVE-2008-4727webappsjava29 ene 2008
Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner
23RIESGO
abrir
Exploit-DBVexDay Proof
ASPired2Protect Login Page - SQL Injection
CVE-2008-0487webappsasp28 ene 2008
Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
eTicket 1.5.6-RC4 - 'index.php' Cross-Site Scripting
CVE-2008-0552webappsphp28 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
VB Marketing - 'tseekdir.cgi' Local File Inclusion
CVE-2008-0488webappscgi28 ene 2008
Directory traversal vulnerability in tseekdir.cgi in VB Marketing allows remote attackers to include and execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Firebird 2.0.3 Relational Database - 'protocol.cpp' XDR Protocol Remote Memory Corruption
CVE-2008-0387remotemultiple28 ene 2008
Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 m
35RIESGO
abrir
Exploit-DBVexDay Proof
Mambo Module MOStlyCE 2.4 - 'connector.php' Cross-Site Scripting
CVE-2008-7213webappsphp28 ene 2008
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connec
23RIESGO
abrir
Exploit-DBVexDay Proof
ClanSphere 2007.4.4 - 'install.php' Local File Inclusion
CVE-2008-0489webappsphp28 ene 2008
Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
F5 BIG-IP Application Security Manager 9.4.3 - 'report_type' Cross-Site Scripting
CVE-2008-0539webappsphp26 ene 2008
Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9
23RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox 2.4.2 - Cross-Site Scripting (2)
CVE-2008-0540webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0738webappsasp25 ene 2008
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0739webappsasp25 ene 2008
SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions
23RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox 2.4.2 - Cross-Site Scripting (1)
CVE-2008-0540webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
WebCalendar 1.1.6 - 'pref.php' Cross-Site Scripting
CVE-2007-6696webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
WebCalendar 1.1.6 - 'search.php' Cross-Site Scripting
CVE-2007-6696webappsphp25 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Pre Hotel and Resorts - 'user_login.asp' Multiple SQL Injection Vulnerabilities
CVE-2008-0744webappsasp25 ene 2008
SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS Mobile Safari - Memory Exhaustion Remote Denial of Service
CVE-2008-0729dosios24 ene 2008
Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion an
23RIESGO
abrir
Exploit-DBVexDay Proof
SDL_image 1.2.6 - Invalid '.GIF' File LWZ Minimum Code Size Remote Buffer Overflow
CVE-2007-6697doslinux23 ene 2008
Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a de
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.2.5 - cURL 'safe_mode' Security Bypass
CVE-2007-4850remotephp23 ene 2008
curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass s
23RIESGO
abrir
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) 1.5/2.x - Multiple Vulnerabilities
CVE-2008-0406remotewindows23 ene 2008
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a den
23RIESGO
abrir
Exploit-DBVexDay Proof
Novemberborn sIFR 2.0.2/3 - 'txt' Cross-Site Scripting
CVE-2008-0438remotemultiple22 ene 2008
Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
DeluxeBB 1.1 - 'attachments_header.php' Cross-Site Scripting
CVE-2008-0439webappsphp22 ene 2008
Cross-site scripting (XSS) vulnerability in templates/default/admincp/attachments_header.php in DeluxeBB 1.1 allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
PacerCMS 0.6 - 'id' Multiple SQL Injections
CVE-2008-0451webappsphp22 ene 2008
Multiple SQL injection vulnerabilities in PacerCMS 0.6 allow remote authenticated users to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.2.6 mod_negotiation - HTML Injection / HTTP Response Splitting
CVE-2008-0455remotelinux22 ene 2008
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in th
35RIESGO
abrir
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.10 - 'cpg1410_xek.php' SQL Injection
CVE-2008-0504webappsphp21 ene 2008
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated admini
23RIESGO
abrir
Exploit-DBVexDay Proof
Singapore 0.10.1 Modern Template - 'gallery' Cross-Site Scripting
CVE-2008-0400webappsphp21 ene 2008
Cross-site scripting (XSS) vulnerability in header.tpl.php in the modern template for Singapore 0.10.1 allows remote att
23RIESGO
abrir
Exploit-DBVexDay Proof
Alice Gate2 Plus Wi-Fi Router - Cross-Site Request Forgery
CVE-2008-7165webappscgi21 ene 2008
Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the administrator panel in TELECOM ITALIA Alice Gate2 Plus Wi-Fi
23RIESGO
abrir
Exploit-DBVexDay Proof
MegaBBS 1.5.14b - 'upload.asp' Cross-Site Scripting
CVE-2008-0436webappsasp21 ene 2008
Cross-site scripting (XSS) vulnerability in profile-upload/upload.asp in PD9 Software MegaBBS 1.5.14b allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Mini File Host 1.2.1 - 'language' Local File Inclusion
CVE-2008-0357webappsphp20 ene 2008
Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Nucleus CMS 3.22 - 'action.php' Cross-Site Scripting
CVE-2008-0497webappsphp20 ene 2008
Cross-site scripting (XSS) vulnerability in action.php in Nucleus CMS 3.31 allows remote attackers to inject arbitrary w
23RIESGO
abrir
anteriorpágina 322 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.