Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
24.451 exploits
Exploit-DBVexDay Proof
Lynx 2.8 - '.mailcap'/'.mime.type' Local Code Execution
CVE-2006-7234remotelinux03 nov 2008
Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious
23RIESGO
abrir
Exploit-DBVexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
CVE-2008-6294webappsphp03 nov 2008
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir
Exploit-DBVexDay Proof
Acc Statistics 1.1 - Insecure Cookie Handling
CVE-2008-6292webappsphp03 nov 2008
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir
Exploit-DBVexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
CVE-2008-6293webappsphp03 nov 2008
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir
Exploit-DBVexDay Proof
Acc Statistics 1.1 - Insecure Cookie Handling
CVE-2008-6293webappsphp03 nov 2008
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir
Exploit-DBVexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
CVE-2011-5289remotewindows03 nov 2008
The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.
23RIESGO
abrir
Exploit-DBVexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
CVE-2008-6294webappsphp03 nov 2008
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir
Exploit-DBVexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
CVE-2008-6292webappsphp03 nov 2008
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Downline Builder Pro - 'tr.php' SQL Injection
CVE-2008-4895webappsphp02 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Short Url & Url Tracker - SQL Injection
CVE-2008-4885webappsphp01 nov 2008
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4881webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4884webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Graugon PHP Article Publisher Pro 1.5 - Insecure Cookie Handling
CVE-2009-4808webappsphp01 nov 2008
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir
Exploit-DBVexDay Proof
GE Fanuc Real Time Information Portal 2.6 - 'writeFile()' API (Metasploit)
CVE-2008-0175remotewindows01 nov 2008
Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote at
28RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4895webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4900webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4883webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
YourFreeWorld Banner Management - SQL Injection
CVE-2008-4882webappsphp01 nov 2008
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Tribiq CMS 5.0.10a (Windows) - Local File Inclusion
CVE-2008-4893webappsphp31 oct 2008
Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS
23RIESGO
abrir
Exploit-DBVexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
CVE-2008-4896webappsphp31 oct 2008
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
phpWebSite 0.9.3 - 'links.php' SQL Injection
CVE-2008-6266webappsphp31 oct 2008
SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Opera Web Browser 9.x - History Search and Links Panel Cross-Site Scripting
CVE-2008-4795remotelinux30 oct 2008
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
SonicWALL - Content Filtering Blocked Site Error Page Cross-Site Scripting
CVE-2008-4918remotehardware30 oct 2008
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DebugDiag 1.0 - 'CrashHangExt.dll' ActiveX Control Remote Denial of Service
CVE-2008-4800doswindows30 oct 2008
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attack
28RIESGO
abrir
Exploit-DBVexDay Proof
Dovecot 1.1.x - Invalid Message Address Parsing Denial of Service
CVE-2008-4907doslinux30 oct 2008
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows
23RIESGO
abrir
Exploit-DBVexDay Proof
PacketTrap TFTPD 2.2.5459.0 - Remote Denial of Service
CVE-2008-1311doswindows29 oct 2008
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RIESGO
abrir
Exploit-DBVexDay Proof
Extrakt Framework 0.7 - 'index.php' Cross-Site Scripting
CVE-2008-6217webappsphp29 oct 2008
Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
KKE Info Media Kmita Gallery - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-5068webappsphp29 oct 2008
Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Nuke League Module - 'tid' Cross-Site Scripting
CVE-2008-5039webappsphp28 oct 2008
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Elkagroup Image Gallery 1.0 - 'view.php' SQL Injection
CVE-2008-5037webappsphp28 oct 2008
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
anteriorpágina 465 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.