Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
PHP 5.1.6 - 'Chunk_Split()' Integer Overflow
CVE-2007-2872remotephp31 may 2007
Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP JackKnife 2.21 - '(PHPJK) G_Display.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-3001webappsphp31 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP JackKnife 2.21 - '/(PHPJK) UserArea/Authenticate.php?sUName' Cross-Site Scripting
CVE-2007-3001webappsphp31 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in PHP JackKnife (PHPJK) allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
LeadTools Raster OCR Document Object Library - Memory Corruption
CVE-2007-2981doswindows30 may 2007
Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e
23RIESGO
abrir
Exploit-DBVexDay Proof
Particle Gallery 1.0 - 'search.php' Cross-Site Scripting
CVE-2007-2962webappsphp30 may 2007
Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
F-Secure Policy Manager 7.00 - 'FSMSH.dll' Remote Denial of Service
CVE-2007-2964doswindows30 may 2007
The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial o
23RIESGO
abrir
Exploit-DBVexDay Proof
Zenturi ProgramChecker - ActiveX File Download/Overwrite
CVE-2007-3076remotewindows30 may 2007
A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to
23RIESGO
abrir
Exploit-DBVexDay Proof
LeadTools Raster ISIS Object 'LTRIS14e.DLL 14.5.0.44' - Remote Buffer Overflow (PoC)
CVE-2007-2980doswindows30 may 2007
Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 al
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX < 2007-005 - 'vpnd' Local Privilege Escalation
CVE-2007-0753localosx30 may 2007
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
UebiMiau 2.7.10 - '/demo/pop3/error.php' Multiple Full Path Disclosures
CVE-2007-3171webappsphp29 may 2007
Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an in
23RIESGO
abrir
Exploit-DBVexDay Proof
CPCommerce 1.1 - 'manufacturer.php' SQL Injection
CVE-2007-2959webappsphp29 may 2007
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
UebiMiau 2.7.10 - '/demo/pop3/error.php?selected_theme' Cross-Site Scripting
CVE-2007-3170webappsphp29 may 2007
Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.9 - VPND Local Format String
CVE-2007-0753localosx29 may 2007
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
British TeleCommunications Consumer Webhelper 2.0.0.7 - Multiple Buffer Overflow Vulnerabilities
CVE-2007-2983remotewindows29 may 2007
Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebco
23RIESGO
abrir
Exploit-DBVexDay Proof
DGNews 1.5.1/2.1 - 'news.php' SQL Injection
CVE-2007-0693webappsphp28 may 2007
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
DGNews 2.1 - 'footer.php' Cross-Site Scripting
CVE-2007-0694webappsphp28 may 2007
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir
Exploit-DBVexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (1)
CVE-2007-2888localwindows28 may 2007
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RIESGO
abrir
Exploit-DBVexDay Proof
Mutt 1.4.2 - Mutt_Gecos_Name Function Local Buffer Overflow
CVE-2007-2683locallinux28 may 2007
Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, w
23RIESGO
abrir
Exploit-DBVexDay Proof
DGNews 2.1 - 'NewsID' SQL Injection
CVE-2007-0693webappsphp28 may 2007
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (2)
CVE-2007-2888localwindows28 may 2007
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache 2.0.58 mod_rewrite (Windows 2003) - Remote Overflow
CVE-2006-3747remotewindows26 may 2007
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RIESGO
abrir
Exploit-DBVexDay Proof
Pligg CMS 9.5 - Reset Forgotten Password Security Bypass
CVE-2007-5579webappsphp25 may 2007
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails 1.2.3 To_JSON - Script Injection
CVE-2007-3227remotelinux25 may 2007
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before ed
23RIESGO
abrir
Exploit-DBVexDay Proof
BoastMachine 3.1 - 'index.php' Cross-Site Scripting
CVE-2007-2932webappsphp25 may 2007
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
GNUTurk - 'Mods.php' Cross-Site Scripting
CVE-2007-2879webappsphp25 may 2007
Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
phpPgAdmin 4.1.1 - 'Redirect.php' Cross-Site Scripting
CVE-2007-5728webappsphp25 may 2007
Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inje
43RIESGO
abrir
Exploit-DBVexDay Proof
Dart Communications PowerTCP - ZIP Compression Remote Buffer Overflow
CVE-2007-2856remotewindows25 may 2007
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Interne
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - pppd Plugin Loading Privilege Escalation
CVE-2007-0752localosx25 may 2007
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker
23RIESGO
abrir
Exploit-DBVexDay Proof
Dart Communications PowerTCP - Service Control Remote Buffer Overflow
CVE-2007-2856remotewindows24 may 2007
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Interne
23RIESGO
abrir
Exploit-DBVexDay Proof
LeadTools Raster Dialog File Object - ActiveX Remote Buffer Overflow (PoC)
CVE-2007-2895doswindows24 may 2007
Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows rem
23RIESGO
abrir
anteriorpágina 349 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.