Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Dokeos 1.x - '/forum/viewthread.php?forum' Cross-Site Scripting
CVE-2007-6574webappsphp22 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
WinUAE 1.4.4 - 'zfile.c' Stack Buffer Overflow
CVE-2007-6537dosmultiple21 dic 2007
Stack-based buffer overflow in the zfile_gunzip function in zfile.c in WinUAE 1.4.4 and earlier allows user-assisted rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Sendmail with clamav-milter < 0.91.2 - Remote Command Execution
CVE-2007-4560remotemultiple21 dic 2007
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary command
60RIESGO
abrir
Exploit-DBVexDay Proof
MRBS 1.2.x - 'view_entry.php' SQL Injection
CVE-2007-6538webappsphp21 dic 2007
SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
SiteScape Forum - 'dispatch.cgi' Tcl Command Injection
CVE-2007-6515webappscgi20 dic 2007
support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator charact
23RIESGO
abrir
Exploit-DBVexDay Proof
HP eSupportDiagnostics 1.0.11 - 'hpediag.dll' ActiveX Control Multiple Information Disclosure Vulnerabilities
CVE-2007-6513remotewindows20 dic 2007
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
iDevSpot iSupport 1.8 - 'index.php' Local File Inclusion
CVE-2007-6539webappsphp20 dic 2007
PHP local file inclusion vulnerability in index.php in IDevspot iSupport 1.8 allows remote attackers to include local fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.2.6 (Windows) - Share PHP File Extension Mapping Information Disclosure
CVE-2007-6514remotewindows19 dic 2007
Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote att
35RIESGO
abrir
Exploit-DBVexDay Proof
ProWizard 4 PC 1.62 - Multiple Remote Stack Buffer Overflow Vulnerabilities
CVE-2007-6510dosmultiple19 dic 2007
Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 - IPv6 Hop-By-Hop Header Remote Denial of Service
CVE-2007-4567doslinux19 dic 2007
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-b
28RIESGO
abrir
Exploit-DBVexDay Proof
RaidenHTTPD 2.0.19 - 'ulang' Remote Command Execution
CVE-2007-6453remotewindows18 dic 2007
Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function i
23RIESGO
abrir
Exploit-DBVexDay Proof
RavWare Software - '.MAS' Flic Control Remote Buffer Overflow
CVE-2007-6516remotewindows18 dic 2007
Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Mambo 4.6.2 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-6455webappsphp18 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Rosoft Media Player 4.1.7 - '.m3u' Local Stack Overflow
CVE-2007-6478localwindows18 dic 2007
Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Surgemail 38k4 - webmail Host header Denial of Service
CVE-2007-6457doswindows18 dic 2007
Stack-based buffer overflow in the webmail feature in SurgeMail 38k4 allows remote attackers to cause a denial of servic
23RIESGO
abrir
Exploit-DBVexDay Proof
iMesh 7.1.0.x - 'IMWeb.dll 7.0.0.x' Remote Heap Overflow
CVE-2007-6493remotewindows18 dic 2007
The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earli
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 7.0.x/8.0.x/9.0.x - ActiveX Control 'navigateToURL' API Cross Domain Scripting
CVE-2007-6244remotelinux18 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allo
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 8.0.34.0/9.0.x - 'main.swf?baseurl' asfunction: Protocol Handler Cross-Site Scripting
CVE-2007-6244remotemultiple18 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allo
28RIESGO
abrir
Exploit-DBVexDay Proof
iMesh 7 - 'IMWebControl' ActiveX Control Code Execution
CVE-2007-6493remotewindows17 dic 2007
The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earli
23RIESGO
abrir
Exploit-DBVexDay Proof
Appian Business Process Management Suite 5.6 - Remote Denial of Service
CVE-2007-6509dosmultiple17 dic 2007
Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers t
50RIESGO
abrir
Exploit-DBVexDay Proof
Perl Net::DNS 0.48/0.59/0.60 - DNS Response Remote Denial of Service
CVE-2007-6341doslinux17 dic 2007
Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
PeerCast 0.12 - HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
CVE-2007-6454doslinux17 dic 2007
Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and e
28RIESGO
abrir
Exploit-DBVexDay Proof
phPay 2.2.1 - Windows Installations Local File Inclusion
CVE-2007-6471webappsphp15 dic 2007
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory
23RIESGO
abrir
Exploit-DBVexDay Proof
phpRPG 0.8 - '/tmp' Directory PHPSESSID Cookie Session Hijacking
CVE-2007-6470webappsphp15 dic 2007
phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
wwwstats 3.21 - 'Clickstats.php' Multiple HTML Injection Vulnerabilities
CVE-2007-6307webappsphp15 dic 2007
Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Samba 3.0.27a - 'send_mailslot()' Remote Buffer Overflow
CVE-2007-6015doslinux14 dic 2007
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logon
28RIESGO
abrir
Exploit-DBVexDay Proof
MKPortal 1.1 Gallery Module - SQL Injection
CVE-2007-6467webappsphp13 dic 2007
SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX xnu 1228.0 - 'super_blob' Local kernel Denial of Service (PoC)
CVE-2007-6359dososx12 dic 2007
The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
SquirrelMail G/PGP Encryption Plugin - 'deletekey()' Command Injection
CVE-2005-1924webappsphp11 dic 2007
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands v
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.3.1 - Charset SQL Injection
CVE-2007-6318webappsphp11 dic 2007
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute a
23RIESGO
abrir
anteriorpágina 326 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.