Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Indexu 5.0/5.3 - 'new.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-0364webappsphp16 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in nicecoder.com INDEXU 5.3 and earlier allow remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercur Messaging 2005 - IMAP Remote Buffer Overflow
CVE-2006-1255remotewindows15 ene 2007
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RIESGO
abrir
Exploit-DBVexDay Proof
Oftpd 0.3.7 - Unsupported Address Family Remote Denial of Service
CVE-2006-6767doslinux15 ene 2007
oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV comma
23RIESGO
abrir
Exploit-DBVexDay Proof
Jax Petition 3.06 Book - 'smileys.php?languagepack' Local File Inclusion
CVE-2007-0335webappsphp15 ene 2007
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Outpost Firewall PRO 4.0 - Local Privilege Escalation
CVE-2007-0333localwindows15 ene 2007
Agnitum Outpost Firewall PRO 4.0 allows local users to bypass access restrictions and insert Trojan horse drivers into t
23RIESGO
abrir
Exploit-DBVexDay Proof
ProSysInfo TFTP Server TFTPDWIN 0.4.2 - Remote Buffer Overflow (1)
CVE-2006-4948remotewindows15 ene 2007
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to
50RIESGO
abrir
Exploit-DBVexDay Proof
InstantASP 4.1 - 'Logon.aspx?sessionid' Cross-Site Scripting
CVE-2007-0302webappsasp15 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SpamBam - Key Calculation Security Bypass
CVE-2008-4616webappsphp15 ene 2007
The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-su
23RIESGO
abrir
Exploit-DBVexDay Proof
InstantASP 4.1 - 'Members1.aspx' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-0302webappsasp15 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in InstantASP 4.1.0 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
Kaspersky AntiVirus 6.0 - Local Privilege Escalation
CVE-2007-1881localwindows15 ene 2007
Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for Fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit build 18794 - WebCore Remote Denial of Service
CVE-2007-0342HIGHdososx15 ene 2007
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and applicati
41RIESGO
abrir
Exploit-DBVexDay Proof
Jax Petition Book 3.06 - 'jax_petitionbook.php?languagepack' Local File Inclusion
CVE-2007-0335webappsphp15 ene 2007
Multiple directory traversal vulnerabilities in Jax Petition Book 1.0.3.06 allow remote attackers to include and execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Libgtop2 Library - Local Buffer Overflow
CVE-2007-0235doslinux15 ene 2007
Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local user
23RIESGO
abrir
Exploit-DBVexDay Proof
KarjaSoft Sami FTP Server 2.0.2 - USER/PASS Remote Buffer Overflow (PoC)
CVE-2006-0441doswindows14 ene 2007
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - DMG UFS UFS_LookUp Denial of Service
CVE-2007-0267dososx13 ene 2007
The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 7.x - 'Block-Old_Articles.php' SQL Injection
CVE-2007-0309webappsphp13 ene 2007
SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_
23RIESGO
abrir
Exploit-DBVexDay Proof
All In One Control Panel 1.3.x - 'cp_downloads.php?did' SQL Injection
CVE-2007-0316webappsphp12 ene 2007
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is
23RIESGO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.8.6a - Denial of Service (1)
CVE-2007-0256doswindows12 ene 2007
VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.
28RIESGO
abrir
Exploit-DBVexDay Proof
WinZip 9.0 - Command Line Remote Buffer Overflow
CVE-2007-0264doswindows12 ene 2007
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and po
23RIESGO
abrir
Exploit-DBVexDay Proof
CA BrightStor ARCserve Backup - Message Engine/Tape Engine Remote Buffer Overflow
CVE-2007-0168doswindows11 ene 2007
The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5
28RIESGO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.8.6a - Denial of Service (2)
CVE-2007-0256doswindows11 ene 2007
VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file.
28RIESGO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.21 - 'privmsg.php' HTML Injection
CVE-2006-6421webappsphp11 ene 2007
Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows r
28RIESGO
abrir
Exploit-DBVexDay Proof
eIQnetworks Network Security Analyzer - Null Pointer Dereference
CVE-2007-0228doswindows10 ene 2007
The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - DMG UFS FFS_MountFS Integer Overflow
CVE-2007-0229dososx10 ene 2007
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of
23RIESGO
abrir
Exploit-DBVexDay Proof
iPlanet Web Server 4.1 - Search Module Cross-Site Scripting
CVE-2007-0183remotemultiple09 ene 2007
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/upload_photo.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 ene 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
FileCOPA FTP Server 1.01 - 'LIST' Remote Buffer Overflow (Metasploit)
CVE-2006-3726remotewindows09 ene 2007
Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to
50RIESGO
abrir
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/register.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 ene 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Magic Photo Storage Website - '/user/logout.php?_config[site_path]' Remote File Inclusion
CVE-2007-0182webappsphp09 ene 2007
Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - Apple Finder DMG Volume Name Memory Corruption (PoC)
CVE-2007-0197dososx09 ene 2007
Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly e
23RIESGO
abrir
anteriorpágina 552 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.