Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Xtacacsd 4.1.2 - 'report()' Remote Buffer Overflow (Metasploit)
CVE-2008-7232remotebsd08 ene 2008
Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code v
43RIESGO
abrir
Exploit-DBVexDay Proof
IceWarp Mail Server 9.1.1 - '/admin/index.html' Cross-Site Scripting
CVE-2008-0218webappsphp08 ene 2008
Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
SysHotel On Line System - 'index.php' Local File Inclusion
CVE-2008-0184webappsphp08 ene 2008
Absolute path traversal vulnerability in index.php in Sys-Hotel on Line System allows remote attackers to read arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
eTicket 1.5.5.2 - 'admin.php' Cross-Site Request Forgery
CVE-2008-0266webappsphp07 ene 2008
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the ad
23RIESGO
abrir
Exploit-DBVexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
CVE-2007-5759remotelinux07 ene 2008
20RIESGO
abrir
Exploit-DBVexDay Proof
eTicket 1.5.5.2 - 'admin.php' Multiple SQL Injections
CVE-2008-0267webappsphp07 ene 2008
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
eTicket 1.5.5.2 - 'search.php' Multiple SQL Injections
CVE-2008-0267webappsphp07 ene 2008
Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
SynCE 0.92 - 'vdccm' Daemon Remote Command Injection
CVE-2008-1136remotelinux07 ene 2008
The Utils::runScripts function in src/utils.cpp in vdccm 0.92 through 0.10.0 in SynCE (SynCE-dccm) allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
eTicket 1.5.5.2 - 'view.php?s' Cross-Site Scripting
CVE-2008-0268webappsphp07 ene 2008
Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Horde Web-Mail 3.x - 'go.php' Remote File Disclosure
CVE-2006-1260webappsphp06 ene 2008
Horde Application Framework 3.0.9 allows remote attackers to read arbitrary files via a null character in the url parame
28RIESGO
abrir
Exploit-DBVexDay Proof
NetRisk 1.9.7 - Remote Password Change
CVE-2008-7155webappsphp05 ene 2008
NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 6.0 yaSSL 1.7.5 - Hello Message Buffer Overflow (Metasploit)
CVE-2008-0226remotelinux04 ene 2008
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attacke
60RIESGO
abrir
Exploit-DBVexDay Proof
Pragma Systems FortressSSH 5.0 - 'msvcrt.dll' Exception Handling Remote Denial of Service
CVE-2008-0132dosmultiple04 ene 2008
Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message wind
23RIESGO
abrir
Exploit-DBVexDay Proof
Pragma TelnetServer 7.0.4.589 - NULL-Pointer Dereference Denial of Service
CVE-2008-0153dosmultiple04 ene 2008
telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and res
28RIESGO
abrir
Exploit-DBVexDay Proof
Foxit WAC Server 2.0 Build 3503 - Denial of Service
CVE-2008-0151dosmultiple04 ene 2008
Heap-based buffer overflow in Foxit WAC Server 2.1.0.910, 2.0 Build 3503, and earlier allows remote attackers to cause a
23RIESGO
abrir
Exploit-DBVexDay Proof
W3-mSQL - Error Page Cross-Site Scripting
CVE-2008-0146webappscgi03 ene 2008
Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.2.3 - '/wp-admin/post.php?popuptitle' Cross-Site Scripting
CVE-2008-0192webappsphp03 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.2.3 - '/wp-admin/page-new.php?popuptitle' Cross-Site Scripting
CVE-2008-0192webappsphp03 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
PRO-Search 0.17 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0207webappsphp03 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.2.3 - '/wp-admin/edit.php?backup' Cross-Site Scripting
CVE-2008-0193webappsphp03 ene 2008
Cross-site scripting (XSS) vulnerability in wp-db-backup.php in WordPress 2.0.11 and earlier, and possibly 2.1.x through
23RIESGO
abrir
Exploit-DBVexDay Proof
AwesomeTemplateEngine 1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-0190webappsphp03 ene 2008
Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow rem
23RIESGO
abrir
Exploit-DBVexDay Proof
MODx 0.9.6.1 - 'htcmime.php' Source Code Information Disclosure
CVE-2008-0094webappsphp02 ene 2008
Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) inc
23RIESGO
abrir
Exploit-DBVexDay Proof
White_Dune 0.29beta791 - Multiple Local Code Execution Vulnerabilities
CVE-2008-0100localmultiple02 ene 2008
Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
InfoSoft FusionCharts 3 - '.swf' Flash File Remote Code Execution
CVE-2008-6060remotemultiple02 ene 2008
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft Fu
23RIESGO
abrir
Exploit-DBVexDay Proof
Camtasia Studio 4.0.2 - 'csPreloader' Remote Code Execution
CVE-2008-6061remotemultiple02 ene 2008
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by
23RIESGO
abrir
Exploit-DBVexDay Proof
MODx 0.9.6.1 - 'AjaxSearch.php' Local File Inclusion
CVE-2008-0094webappsphp02 ene 2008
Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) inc
23RIESGO
abrir
Exploit-DBVexDay Proof
InstantSoftwares Dating Site - Login SQL Injection
CVE-2007-6671webappsasp31 dic 2007
SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
LiveCart 1.0.1 - 'email' Cross-Site Scripting
CVE-2007-6646webappsphp31 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
LiveCart 1.0.1 - 'return' Cross-Site Scripting (1)
CVE-2007-6646webappsphp31 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
MilliScripts - 'dir.php' Cross-Site Scripting
CVE-2007-6641webappsphp31 dic 2007
Cross-site scripting (XSS) vulnerability in dir.php in milliscripts Redirection allows remote attackers to inject arbitr
23RIESGO
abrir
anteriorpágina 324 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.