Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
24.455 exploits
Exploit-DBVexDay Proof
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
CVE-2007-0015remotewindows03 ene 2007
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RIESGO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.8.6 (x86) - 'udp://' Format String
CVE-2007-0017localosx02 ene 2007
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA
28RIESGO
abrir
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'catalogue.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'salesadmin.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'editcatalogue.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.8.6 (PPC) - 'udp://' Format String (PoC)
CVE-2007-0017dososx02 ene 2007
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA
28RIESGO
abrir
Exploit-DBVexDay Proof
VCard Pro - 'gbrowse.php' Cross-Site Scripting
CVE-2007-0054webappsphp02 ene 2007
Cross-site scripting (XSS) vulnerability in gbrowse.php in Belchior Foundry vCard PRO allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'search.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'shipping.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Georgia SoftWorks Secure Shell Server 7.1.3 - Multiple Remote Code Execution Vulnerabilities
CVE-2008-0096remotelinux02 ene 2007
Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
MyServer 0.9.8 - Post.MSCGI Cross-Site Scripting
CVE-2007-3364remotemultiple02 ene 2007
Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
AShop Deluxe 4.5 - 'basket.php' Cross-Site Scripting
CVE-2007-0056webappsphp02 ene 2007
Multiple cross-site scripting (XSS) vulnerabilities in AShop Deluxe 4.5 and AShop Administration Panel allow remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Buffer Overflow (2)
CVE-2006-5551remotewindows01 ene 2007
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RIESGO
abrir
Exploit-DBVexDay Proof
Kerio Personal Firewall 4.3 - 'IPHLPAPI.dll' Local Privilege Escalation
CVE-2007-0081localwindows01 ene 2007
Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a
23RIESGO
abrir
Exploit-DBVexDay Proof
WWWBoard 2.0 - 'passwd.txt' Remote Password Disclosure
CVE-1999-0953webappscgi01 ene 2007
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'Csrss.exe/winsrv.dll' NtRaiseHardError Double-Free
CVE-2006-6797doswindows31 dic 2006
The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash
23RIESGO
abrir
Exploit-DBVexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2007-0138doswindows31 dic 2006
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with (1) AbfrageForm or (2) EingabeForm, allows
23RIESGO
abrir
Exploit-DBVexDay Proof
WinZip 10.0 - FileView ActiveX Controls Remote Overflow
CVE-2006-6884remotewindows31 dic 2006
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZ
23RIESGO
abrir
Exploit-DBVexDay Proof
Rediff Bol Downloader - ActiveX Control Execute Local File
CVE-2006-6838remotewindows31 dic 2006
Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive inf
23RIESGO
abrir
Exploit-DBVexDay Proof
Spooky 2.7 - 'login/register.asp' SQL Injection
CVE-2006-6861webappsasp30 dic 2006
Multiple SQL injection vulnerabilities in Outfront Spooky Login 2.7 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
x-news 1.1 - 'users.txt' Remote Password Disclosure
CVE-2002-1656webappsphp30 dic 2006
X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the pas
23RIESGO
abrir
Exploit-DBVexDay Proof
Mobilelib Gold - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-6851webappsphp29 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in contact_us.php in ac4p Mobilelib gold 2 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Hosting Controller 7C - 'FolderManager.aspx' Directory Traversal
CVE-2006-6814webappsasp27 dic 2006
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticat
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'week.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'search.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'print.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'year.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'month.php' Cross-Site Scripting
CVE-2006-6824webappsphp27 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP iCalendar 1.1/2.x - 'getdate' Cross-Site Scripting
CVE-2006-6824webappsphp27 dic 2006
Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow r
23RIESGO
abrir
Exploit-DBVexDay Proof
DMXReady Secure Login Manager 1.0 - 'login.asp?sent' SQL Injection
CVE-2006-6816webappsasp27 dic 2006
Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir
anteriorpágina 555 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.