Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
Exploit-DB
WordPress Plugin Forum Server 1.6.5 - SQL Injection
CVE-2011-1047—webappsphp24 feb 2011
Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress al
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Netware - RPC XNFS xdrDecodeString
CVE-2010-4227—dosnetware24 feb 2011
The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of s
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CesarFTP 0.99g - 'MKD' Remote Buffer Overflow (Metasploit) (2)
CVE-2006-2961—remotewindows23 feb 2011
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Lotus Sametime Server 8.0 - 'stcenter.nsf' Cross-Site Scripting
CVE-2011-1106—webappsphp22 feb 2011
Cross-site scripting (XSS) vulnerability in stcenter.nsf in the server in IBM Lotus Sametime allows remote attackers to
23RIESGO
abrir ↗
Metasploit300
Solar FTP Server Malformed USER Denial of Service
CVE-2011-10029HIGH22 feb 2011
Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox - Interleaving 'document.write' / 'appendChild' (Metasploit)
CVE-2010-3765CRITICALbajo ataqueremotewindows22 feb 2011
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Lotus Sametime - '/stconf.nsf/WebMessage?messageString' Cross-Site Scripting
CVE-2011-1038—remotemultiple21 feb 2011
Multiple cross-site scripting (XSS) vulnerabilities in stconf.nsf in the server in IBM Lotus Sametime 8.0.1 allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell ZENworks 10/11 - TFTPD Remote Code Execution
CVE-2010-4323—doswindows18 feb 2011
Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Lotus Domino LDAP - Bind Request Remote Code Execution
CVE-2011-0917—doswindows18 feb 2011
Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WSN Guest 1.24 - 'wsnuser' Cookie SQL Injection
CVE-2011-1060—webappsphp18 feb 2011
SQL injection vulnerability in the member function in classes/member.php in WSN Guest 1.24 allows remote attackers to ex
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Iprint - LPD Remote Code Execution
CVE-2010-4328—doslinux18 feb 2011
Multiple stack-based buffer overflows in opt/novell/iprint/bin/ipsmd in Novell iPrint for Linux Open Enterprise Server 2
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Server Service - NetpwPathCanonicalize Overflow (MS06-040) (Metasploit)
CVE-2006-3439—remotewindows17 feb 2011
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - Print Spooler Service Impersonation (MS10-061) (Metasploit)
CVE-2010-2729—remotewindows17 feb 2011
The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windo
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.3.5 - 'grapheme_extract()' Null Pointer Dereference
CVE-2011-0420—doslinux17 feb 2011
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependen
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.3.5 - 'grapheme_extract()' Null Pointer Dereference Denial of Service
CVE-2011-0420—dosphp17 feb 2011
The grapheme_extract function in the Internationalization extension (Intl) for ICU for PHP 5.3.5 allows context-dependen
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Rae Media Real Estate Multi Agent - SQL Injection
CVE-2010-4738—webappsasp16 feb 2011
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Rae Media Real Estate Single Agent - SQL Injection
CVE-2010-4738—webappsasp16 feb 2011
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ruby on Rails 3.0.5 - 'WEBrick::HTTPRequest' Module HTTP Header Injection
CVE-2011-3187—remotemultiple16 feb 2011
The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lingxia I.C.E CMS - Blind SQL Injection
CVE-2011-1055—webappscfm15 feb 2011
SQL injection vulnerability in api/ice_media.cfc in Lingxia I.C.E CMS 1.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Metasploit600
Sun Java Applet2ClassLoader Remote Code Execution
CVE-2010-4452—15 feb 2011
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2003 - AD BROWSER ELECTION Remote Heap Overflow
CVE-2011-0654—doswindows14 feb 2011
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in
50RIESGO
abrir ↗
Exploit-DB
TaskFreak! 0.6.4 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-1062—webappsphp12 feb 2011
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RIESGO
abrir ↗
Exploit-DB
PixelPost 1.7.3 - Multiple POST SQL Injections
CVE-2011-1100—webappsphp12 feb 2011
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TaskFreak! 0.6.4 - 'rss.php' HTTP Referer Header Cross-Site Scripting
CVE-2011-1062—webappsphp12 feb 2011
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TaskFreak! 0.6.4 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-1062—webappsphp12 feb 2011
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TaskFreak! 0.6.4 - 'print_list.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-1062—webappsphp12 feb 2011
Multiple cross-site scripting (XSS) vulnerabilities in include/html/header.php in TaskFreak! 0.6.4 allow remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Horde - Horde_Image::factory driver Argument Local File Inclusion
CVE-2009-0932—webappsphp11 feb 2011
Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware befor
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ManageEngine ADSelfService Plus 4.4 - POST Manipulation Security Question
CVE-2010-3272—webappsphp10 feb 2011
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Bui
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ManageEngine ADSelfService Plus 4.4 - 'EmployeeSearch.cc' Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-3274—webappsphp10 feb 2011
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEng
28RIESGO
abrir ↗
GitHub PoC★ 1
http://www.oracle.com/technetwork/topics/security/alert-cve-2010-4476-305811.html
CVE-2010-4476—10 feb 2011
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and
28RIESGO
abrir ↗
← anteriorpágina 1237 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.