Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Application Enhancer (APE) 2.0.2 - Local Privilege Escalation
CVE-2007-0162localosx08 ene 2007
Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and
23RIESGO
abrir
Exploit-DBVexDay Proof
Opera 9.10 - '.jpg' Image DHT Marker Heap Corruption
CVE-2007-0126dosmultiple08 ene 2007
Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an inval
28RIESGO
abrir
Exploit-DBVexDay Proof
Berlios GPSD 2.7 - Remote Format String (Metasploit)
CVE-2004-1388remotelinux08 ene 2007
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7
50RIESGO
abrir
Exploit-DBVexDay Proof
Packeteer PacketShaper 8.0 - Multiple Buffer Overflow (Denial of Service) (PoC) Vulnerabilities
CVE-2007-0113doshardware08 ene 2007
Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell Access Manager 3 Identity Server - 'IssueInstant' Cross-Site Scripting
CVE-2007-0110remotenovell08 ene 2007
Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 all
23RIESGO
abrir
Exploit-DBVexDay Proof
CreateAuction - 'Cats.asp' SQL Injection
CVE-2007-0112webappsasp08 ene 2007
SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBSD 3.x < 4.0 - 'vga_ioctl()' Local Privilege Escalation
CVE-2007-0085localbsd07 ene 2007
Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when th
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy Banner Pro 2.8 - 'info.php' Remote File Inclusion
CVE-2007-0178webappsphp07 ene 2007
PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow (Metasploit)
CVE-2006-5112remotewindows07 ene 2007
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.0.5 - Trackback UTF-7 SQL Injection
CVE-2007-0107webappsphp07 ene 2007
WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,
23RIESGO
abrir
Exploit-DBVexDay Proof
Multiple PDF Readers - Multiple Remote Buffer Overflows
CVE-2007-0103doslinux06 ene 2007
The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknow
28RIESGO
abrir
Exploit-DBVexDay Proof
Shopstorenow E-Commerce Shopping Cart - 'Orange.asp' SQL Injection
CVE-2007-0142webappsasp06 ene 2007
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag.pl?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 ene 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM 'cron' Local Privilege Escalation
CVE-2007-0117localosx05 ene 2007
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RIESGO
abrir
Exploit-DBVexDay Proof
Kolayindir Download - 'down.asp' SQL Injection
CVE-2007-0140webappsasp05 ene 2007
SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag.cgi?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 ene 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir
Exploit-DBVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0133webappsphp05 ene 2007
Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.11 - SQL Injection
CVE-2007-0122webappsphp05 ene 2007
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated adminis
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'mkpw_mp.cgi?plain' Cross-Site Scripting
CVE-2007-0119webappscgi05 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
RI Blog 1.3 - 'search.asp' Cross-Site Scripting
CVE-2007-0121webappsphp05 ene 2007
Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.4.10 - 'xpl.php' SQL Injection
CVE-2007-3558webappsphp05 ene 2007
SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM Privilege Escalation
CVE-2007-0117localosx05 ene 2007
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag_mp.cgi?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 ene 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'mkpw.pl?plain' Cross-Site Scripting
CVE-2007-0119webappscgi05 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'mkpw.cgi?plain' Cross-Site Scripting
CVE-2007-0119webappscgi05 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
EditTag 1.2 - 'edittag_mp.pl?file' Arbitrary File Disclosure
CVE-2007-0118webappscgi05 ene 2007
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader Plugin 7.0.x - 'acroreader' Cross-Site Scripting
CVE-2007-0046remotewindows05 ene 2007
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows re
35RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Backup Exec System Recovery Manager 7.0 - FileUpload Class Unauthorized File Upload
CVE-2008-0457remotewindows05 ene 2007
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
CVE-2007-0015remotewindows03 ene 2007
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime 7.1.3 - 'HREFTrack' Cross-Zone Scripting
CVE-2007-0059remoteosx03 ene 2007
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitr
23RIESGO
abrir
anteriorpágina 554 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.