Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.183exploits catalogados
37.028CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Microsoft Internet Explorer and Mozilla Firefox - URI Handler Command Injection
CVE-2007-3670remotelinux10 jul 2007
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and cert
28RIESGO
abrir
Exploit-DBVexDay Proof
TippingPoint IPS - Unicode Character Detection Bypass
CVE-2007-3701remotewindows10 jul 2007
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which m
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.20.2 - 'IPv6_Getsockopt_Sticky' Memory Leak
CVE-2007-1000locallinux10 jul 2007
The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users t
23RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java WebStart - JNLP Stack Buffer Overflow (PoC)
CVE-2007-3655doswindows10 jul 2007
Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and e
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 8.0.24 - '.SWF' File Handling Remote Code Execution
CVE-2007-3456remotemultiple10 jul 2007
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a
35RIESGO
abrir
Exploit-DBVexDay Proof
ImgSvr 0.6 - 'Template' Local File Inclusion
CVE-2007-3714webappslinux10 jul 2007
Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via
23RIESGO
abrir
Exploit-DBVexDay Proof
SquirrelMail G/PGP Encryption Plugin 2.0/2.1 - Multiple Remote Command Execution Vulnerabilities
CVE-2007-3636webappsphp09 jul 2007
Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Systeme de vote pour site Web 1.0 - Multiple Remote File Inclusions
CVE-2007-4384webappsphp09 jul 2007
Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Connector mod_jk - 'exec-shield' Remote Overflow
CVE-2007-0774remotelinux08 jul 2007
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apach
60RIESGO
abrir
Exploit-DBVexDay Proof
NeoTracePro 3.25 - ActiveX 'TraceTarget()' Remote Buffer Overflow
CVE-2006-6707remotewindows07 jul 2007
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Ex
50RIESGO
abrir
Exploit-DBVexDay Proof
SAP DB 7.4 - WebTools Remote Overwrite (SEH)
CVE-2007-3614remotewindows07 jul 2007
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir
Exploit-DBVexDay Proof
Levent Veysi Portal 1.0 - 'Oku.asp' SQL Injection
CVE-2007-3629webappsasp07 jul 2007
SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft .Net Framework 2.0 - Multiple Null Byte Injection Vulnerabilities
CVE-2007-0042remotewindows06 jul 2007
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and
45RIESGO
abrir
Exploit-DBVexDay Proof
SAP Message Server - 'Group' Remote Buffer Overflow
CVE-2007-3624remotemultiple05 jul 2007
Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary
35RIESGO
abrir
Exploit-DBVexDay Proof
SAP DB 7.x Web Server - 'WAHTTP.exe' Multiple Buffer Overflow Vulnerabilities
CVE-2007-3614remotewindows05 jul 2007
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir
Exploit-DBVexDay Proof
Maia Mailguard 1.0.2 - 'login.php' Multiple Local File Inclusions
CVE-2007-3619webappsphp05 jul 2007
Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP Internet Graphics Server 7.0 - 'ADM:GETLOGFILE?PARAMS' Cross-Site Scripting
CVE-2007-3613remotemultiple05 jul 2007
Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
GFax 0.7.6 - Temporary Files Local Arbitrary Command Execution
CVE-2007-2839locallinux05 jul 2007
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NetFlow Analyzer 5 - 'netflow/jspui/index.jsp?view' Cross-Site Scripting
CVE-2007-3593webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
OpManager 6/7 - '/admin/DeviceAssociation.do' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3594webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
NetFlow Analyzer 5 - '/jspui/customReport.jsp?rtype' Cross-Site Scripting
CVE-2007-3593webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
OpManager 6/7 - 'admin/ServiceConfiguration.do?Operation' Cross-Site Scripting
CVE-2007-3594webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
NetFlow Analyzer 5 - '/jspui/appConfig.jsp?task' Cross-Site Scripting
CVE-2007-3593webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
NetFlow Analyzer 5 - '/jspui/selectDevice.jsp?rtype' Cross-Site Scripting
CVE-2007-3593webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
NetFlow Analyzer 5 - '/jspui/applicationList.jsp?alpha' Cross-Site Scripting
CVE-2007-3593webappsjsp04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
OpManager 6/7 - reports/ReportViewAction.do Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3594webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
OpManager 6/7 - 'traceRoute.do?name' Cross-Site Scripting
CVE-2007-3594webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
OpManager 6/7 - 'ping.do?name' Cross-Site Scripting
CVE-2007-3594webappsjava04 jul 2007
Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Plume CMS 1.0.4 - 'index.php?_PX_config[manager_path]' Remote File Inclusion
CVE-2006-3562webappsphp03 jul 2007
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
AXIS Camera Control (AxisCamControl.ocx 1.0.2.15) - Remote Buffer Overflow
CVE-2007-2239remotewindows03 jul 2007
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.
28RIESGO
abrir
anteriorpágina 344 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.