Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Mozilla Firefox 2.0 - 'chrome://' URI JavaScript File Request Information Disclosure
CVE-2008-0418remotelinux19 ene 2008
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before
23RIESGO
abrir
Exploit-DBVexDay Proof
BitDefender Products - Update Server HTTP Daemon Directory Traversal
CVE-2008-0396remotewindows19 ene 2008
Directory traversal vulnerability in BitDefender Update Server (http.exe), as used in BitDefender products including Sec
23RIESGO
abrir
Exploit-DBVexDay Proof
phpAutoVideo 2.21 - 'index.php?cat' Cross-Site Scripting
CVE-2008-0432webappsphp18 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in phpAutoVideo 2.21 and earlier allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
CVE-2008-0442webappsphp18 ene 2008
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
phpAutoVideo 2.21 - 'sidebar.php?loadpage' Remote File Inclusion
CVE-2008-0433webappsphp18 ene 2008
PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and ear
23RIESGO
abrir
Exploit-DBVexDay Proof
CORE FORCE Firewall 0.95.167 and Registry Modules - Multiple Local Kernel Buffer Overflow Vulnerabilities
CVE-2008-0365localwindows17 ene 2008
Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) an
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.2.10 - 'moderation.php' Multiple SQL Injections
CVE-2008-0383webappsphp16 ene 2008
Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
8E6 R3000 Internet Filter 2.0.5.33 - URI SecURIty Bypass
CVE-2008-0372remotehardware16 ene 2008
8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restri
23RIESGO
abrir
Exploit-DBVexDay Proof
BitTorrent 6.0 / uTorrent 1.6/1.7 - Peers Window Remote Code Execution
CVE-2008-0364remotewindows16 ene 2008
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in
23RIESGO
abrir
Exploit-DBVexDay Proof
Article Dashboard - '/admin/login.php' Multiple SQL Injections
CVE-2008-0286webappsphp15 ene 2008
SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Peter's Math Anti-Spam 0.1.6 - Audio CAPTCHA Security Bypass
CVE-2008-7216webappsphp15 ene 2008
Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files wi
23RIESGO
abrir
Exploit-DBVexDay Proof
2WIRE Routers - Cross-Site Request Forgery
CVE-2007-4389remotehardware15 ene 2008
Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5,
23RIESGO
abrir
Exploit-DBVexDay Proof
pMachine Pro 2.4.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0334webappsphp14 ene 2008
Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet Fortigate - CRLF Characters URL Filtering Bypass
CVE-2008-7161remotehardware14 ene 2008
Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via
23RIESGO
abrir
Exploit-DBVexDay Proof
F5 BIG-IP 9.4.3 - 'SearchString' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0265remotehardware14 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Running Management 1.0.2 - 'index.php' Cross-Site Scripting
CVE-2008-0258webappsphp13 ene 2008
Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
Moodle 1.8.3 - 'install.php' Cross-Site Scripting
CVE-2008-0123webappsphp12 ene 2008
Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 2.0.4 - KHTML WebKit Remote Denial of Service
CVE-2008-0298dososx12 ene 2008
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a craf
23RIESGO
abrir
Exploit-DBVexDay Proof
Members Area System 1.7 - 'view_func.php' Remote File Inclusion
CVE-2008-0289webappsphp11 ene 2008
PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Qvod Player 2.1.5 - 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow
CVE-2008-4664remotewindows11 ene 2008
Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow
CVE-2008-1709localwindows11 ene 2008
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RIESGO
abrir
Exploit-DBVexDay Proof
SunOS 5.10 - Remote ICMP Kernel Crash
CVE-2007-0634dossolaris10 ene 2008
Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system
23RIESGO
abrir
Exploit-DBVexDay Proof
ID-Commerce 2.0 - 'liste.php' SQL Injection
CVE-2008-0281webappsphp10 ene 2008
SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Database 10 g - XML DB xdb.xdb_pitrig_pkg Package PITRIG_TRUNCATE Function Overflow
CVE-2008-0339remotemultiple10 ene 2008
Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unkn
28RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/account/findForSelect.jsp?resultsForm' Cross-Site Scripting
CVE-2008-0239webappsjsp09 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RIESGO
abrir
Exploit-DBVexDay Proof
Omegasoft Insel 7 - Authentication Bypass / User Enumeration
CVE-2008-1134webappsphp09 ene 2008
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/help/index.jsp?helpUrl' Remote Frame Injection
CVE-2008-0240webappsjsp09 ene 2008
/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/login.jsp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0239webappsjsp09 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java System Identity Manager 6.0/7.0/7.1 - '/idm/user/main.jsp?activeControl' Cross-Site Scripting
CVE-2008-0239webappsjsp09 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.
23RIESGO
abrir
Exploit-DBVexDay Proof
Xine-Lib 1.1.9 - 'rmff_dump_cont()' Remote Heap Buffer Overflow (PoC)
CVE-2008-0225doslinux09 ene 2008
Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows r
28RIESGO
abrir
anteriorpágina 323 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.