Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Netrek 2.12.0 - 'pmessage2()' Remote Limited Format String
CVE-2007-1251doswindows02 mar 2007
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENT
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.1.1 - Arbitrary Command Execution
CVE-2007-1277webappsphp02 mar 2007
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP < 4.5.0 - Unserialize Overflow (Metasploit)
CVE-2007-1286remotephp01 mar 2007
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RIESGO
abrir
Exploit-DBVexDay Proof
Built2go News Manager 1.0 Blog - 'news.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-1248webappsphp01 mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 3/4/5 - ZendEngine Variable Destruction Remote Denial of Service
CVE-2007-1285dosphp01 mar 2007
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (sta
28RIESGO
abrir
Exploit-DBVexDay Proof
Built2go News Manager 1.0 Blog - 'rating.php?nid' Cross-Site Scripting
CVE-2007-1248webappsphp01 mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow
CVE-2006-5276remotewindows01 mar 2007
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RIESGO
abrir
Exploit-DBVexDay Proof
Comodo Firewall Pro 2.4.x - Local Protection Mechanism Bypass
CVE-2007-1330localwindows01 mar 2007
Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver
23RIESGO
abrir
Exploit-DBVexDay Proof
tcpdump - Print-bgp.C Remote Integer Underflow
CVE-2007-3798CRITICALremotelinux01 mar 2007
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arb
70RIESGO
abrir
Exploit-DBVexDay Proof
phpMyFAQ 1.6.7 - SQL Injection / Command Execution
CVE-2006-6912webappsphp01 mar 2007
SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 4 - Userland ZVAL Reference Counter Overflow (PoC)
CVE-2007-1383CRITICALdosmultiple01 mar 2007
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitra
53RIESGO
abrir
Exploit-DBVexDay Proof
aWebNews 1.1 - 'listing.php?path_to_news' Remote File Inclusion
CVE-2007-1247webappsphp01 mar 2007
Multiple PHP remote file inclusion vulnerabilities in aWeb Labs aWebNews 1.5 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 4/5 - Executor Deep Recursion Remote Denial of Service
CVE-2006-1549dosphp01 mar 2007
PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive funct
23RIESGO
abrir
Exploit-DBVexDay Proof
Madwifi 0.9.2.1 - WPA/RSN IE Remote Kernel Buffer Overflow
CVE-2006-6332remotelinux01 mar 2007
Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execut
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache 1.3.34/1.3.33 (Ubuntu / Debian) - CGI TTY Privilege Escalation
CVE-2006-7098locallinux28 feb 2007
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd fro
23RIESGO
abrir
Exploit-DBVexDay Proof
McAfee VirusScan for Mac (Virex) 7.7 - Local Privilege Escalation
CVE-2007-1227localosx28 feb 2007
VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
HyperBook Guestbook 1.3 - GBConfiguration.DAT Hashed Password Information Disclosure
CVE-2007-1192remotewindows28 feb 2007
Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access con
23RIESGO
abrir
Exploit-DBVexDay Proof
3Com TFTP Service (3CTftpSvc) 2.0.1 - Long Transporting Mode
CVE-2006-6183remotewindows28 feb 2007
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RIESGO
abrir
Exploit-DBVexDay Proof
EmbeddedWB Web Browser ActiveX Control - Remote Code Execution
CVE-2007-1190remotewindows28 feb 2007
Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary cod
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat/Adobe Reader 7.0.9 - Information Disclosure
CVE-2007-1199remotewindows28 feb 2007
Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as de
23RIESGO
abrir
Exploit-DBVexDay Proof
Kiwi CatTools TFTP 3.2.8 - Directory Traversal
CVE-2007-0888remotewindows27 feb 2007
Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - Audit Subsystems Local Denial of Service
CVE-2007-0001doslinux27 feb 2007
The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9
23RIESGO
abrir
Exploit-DBVexDay Proof
Nullsoft SHOUTcast 1.9.7 - Logfile HTML Injection
CVE-2007-1229remotewindows27 feb 2007
Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
SQLiteManager 1.2 - Local File Inclusion
CVE-2007-1232webappsphp26 feb 2007
Directory traversal vulnerability in SQLiteManager 1.2.0 allows remote attackers to read arbitrary files via a .. (dot d
35RIESGO
abrir
Exploit-DBVexDay Proof
Audins Audiens 3.3 - 'setup.php?PATH_INFO' Cross-Site Scripting
CVE-2007-1241webappsphp26 feb 2007
Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
SQLiteManager 1.2 - 'main.php' Multiple HTML Injection Vulnerabilities
CVE-2007-1231webappsphp26 feb 2007
Multiple cross-site scripting (XSS) vulnerabilities in SQLiteManager 1.2.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g ACTIVATE_SUBSCRIPTION - SQL Injection (2)
CVE-2005-4832remotemultiple26 feb 2007
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL
50RIESGO
abrir
Exploit-DBVexDay Proof
SolarPay - 'index.php' Local File Inclusion
CVE-2006-7099webappsphp26 feb 2007
Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. (dot d
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 10g Database - 'SUBSCRIPTION_NAME' SQL Injection (2)
CVE-2005-4832remotemultiple26 feb 2007
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g DBMS_METADATA.GET_DDL - SQL Injection (2)
CVE-2006-0549remotemultiple26 feb 2007
SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions,
23RIESGO
abrir
anteriorpágina 365 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.