Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
Exploit-DB
Multiple Vendor Calendar Manager - Remote Code Execution
CVE-2010-4435—remotemultiple09 feb 2011
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MihanTools Script 1.3.3 - SQL Injection
CVE-2011-1048—webappsphp09 feb 2011
SQL injection vulnerability in product.php in MihanTools 1.33 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (via SQL Injection) (Metasploit)
CVE-2000-0402—remotewindows08 feb 2011
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (via SQL Injection) (Metasploit)
CVE-2008-5416—remotewindows08 feb 2011
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - CreateSizedDIBSECTION Stack Buffer Overflow (MS11-006) (Metasploit)
CVE-2010-3970—localwindows08 feb 2011
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CSS Recursive Import Use-After-Free (MS11-003) (Metasploit)
CVE-2010-3971—remotewindows08 feb 2011
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 1.1.6 - 'MKV' Memory Corruption (Metasploit)
CVE-2011-0531—localwindows08 feb 2011
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server - Payload Execution (via SQL Injection) (Metasploit)
CVE-2000-1209—remotewindows08 feb 2011
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3)
60RIESGO
abrir ↗
Metasploit300
xRadio 0.95b Buffer Overflow
CVE-2008-2789—08 feb 2011
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RIESGO
abrir ↗
Metasploit500
EMC Replication Manager Command Execution
CVE-2011-0647—07 feb 2011
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x
50RIESGO
abrir ↗
Metasploit600
HP Data Protector 6 EXEC_CMD Remote Code Execution
CVE-2011-0923—07 feb 2011
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RIESGO
abrir ↗
Metasploit300
HP Data Protector 6.1 EXEC_CMD Command Execution
CVE-2011-0923—07 feb 2011
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RIESGO
abrir ↗
Exploit-DB
ProFTPd - 'mod_sftp' Integer Overflow Denial of Service (PoC)
CVE-2011-1137—doslinux07 feb 2011
Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a deni
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
CVE-2011-0885—remotehardware06 feb 2011
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default pas
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
CVE-2011-0886—remotehardware06 feb 2011
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the SMC SMCD3G-CCR (aka Comcast Busin
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Comcast DOCSIS 3.0 Business Gateways - Multiple Vulnerabilities
CVE-2011-0887—remotehardware06 feb 2011
The web management portal on the SMC SMCD3G-CCR (aka Comcast Business Gateway) with firmware before 1.4.0.49.2 uses pred
23RIESGO
abrir ↗
Metasploit300
VSFTPD 2.3.2 and Earlier STAT Denial of Service
CVE-2011-0762—03 feb 2011
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RIESGO
abrir ↗
Metasploit600
QuickShare File Server 1.2.1 Directory Traversal Vulnerability
CVE-2011-10010CRITICAL03 feb 2011
QuickShare File Server 1.2.1 Path Traversal RCE
63RIESGO
abrir ↗
Exploit-DB
VideoLAN VLC Media Player 1.1 - Subtitle 'StripTags()' Memory Corruption
CVE-2011-0522—dosmultiple03 feb 2011
The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/code
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark 1.4.3 - '.pcap' Memory Corruption
CVE-2011-0538—remotelinux03 feb 2011
Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
CVE-2011-0049—remotemultiple03 feb 2011
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Majordomo2 - 'SMTP/HTTP' Directory Traversal
CVE-2011-0063—remotemultiple03 feb 2011
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct d
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Terminal Server Client - '.rdp' Denial of Service
CVE-2011-0900—doslinux02 feb 2011
Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150
23RIESGO
abrir ↗
Metasploit300
Mozilla Firefox "nsTreeRange" Dangling Pointer Vulnerability
CVE-2011-0073—02 feb 2011
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedaxScript 0.3.2 - Multiple Vulnerabilities
CVE-2011-5313—webappsphp02 feb 2011
Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Terminal Server Client - '.rdp' Denial of Service
CVE-2011-0901—doslinux02 feb 2011
Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tscli
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Zikula CMS 1.2.4 - Cross-Site Request Forgery
CVE-2011-0535—webappsphp02 feb 2011
Cross-site request forgery (CSRF) vulnerability in the Users module in Zikula before 1.2.5 allows remote attackers to hi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tandberg E & EX & C Series Endpoints - Default Root Account Credentials
CVE-2011-0354—remotehardware02 feb 2011
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with softwar
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - TiVo Buffer Overflow (Metasploit)
CVE-2008-4654—localwindows02 feb 2011
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Java - Floating-Point Value Denial of Service
CVE-2010-4476—dosmultiple01 feb 2011
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and
28RIESGO
abrir ↗
← anteriorpágina 1238 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.