Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
Exploit-DB✓ VexDay Proof
Oracle Java - Floating-Point Value Denial of Service
CVE-2010-4476—dosmultiple01 feb 2011
The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and
28RIESGO
abrir ↗
Metasploit300
AOL Desktop 9.6 RTX Buffer Overflow
CVE-2011-10027HIGH31 ene 2011
AOL Desktop 9.6 RTX Stack-Based Buffer Overflow
36RIESGO
abrir ↗
Metasploit600
HP OpenView Performance Insight Server Backdoor Account Code Execution
CVE-2011-0276—31 ene 2011
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RIESGO
abrir ↗
Metasploit400
VideoLAN VLC MKV Memory Corruption
CVE-2011-0531—31 ene 2011
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenVAS Manager - Command Injection
CVE-2011-0018—locallinux31 ene 2011
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authent
23RIESGO
abrir ↗
Metasploit400
Real Networks Netzip Classic 7.5.1 86 File Parsing Buffer Overflow Vulnerability
CVE-2011-10016CRITICAL30 ene 2011
Real Networks Netzip Classic 7.5.1.86 File Parsing Buffer Overflow
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MHTML Protocol Handler Cross-Site Scripting
CVE-2011-0096MEDIUMlocalwindows29 ene 2011
The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Wind
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AWCM 2.2 Final - Local File Inclusion
CVE-2011-0903—webappsphp26 ene 2011
Multiple directory traversal vulnerabilities in AR Web Content Manager (AWCM) 2.2 allow remote attackers to read arbitra
23RIESGO
abrir ↗
Exploit-DB
Oracle Document Capture 10.1.3.5 - Insecure Method / Buffer Overflow
CVE-2010-3599—remotewindows26 ene 2011
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RIESGO
abrir ↗
Exploit-DB
Oracle Document Capture - Actbar2.ocx Insecure Method
CVE-2010-3591—remotewindows26 ene 2011
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RIESGO
abrir ↗
Exploit-DB
Oracle - Document Capture Insecure READ Method
CVE-2010-3595—remotewindows26 ene 2011
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RIESGO
abrir ↗
Exploit-DB
Oracle Document Capture - 'empop3.dll' Insecure Methods
CVE-2010-3591—remotewindows26 ene 2011
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 all
28RIESGO
abrir ↗
Exploit-DB
Sun Microsystems SunScreen Firewall - Privilege Escalation
CVE-2011-0902—remotemultiple25 ene 2011
Multiple untrusted search path vulnerabilities in the Java Service in Sun Microsystems SunScreen Firewall on SunOS 5.9 a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PivotX 2.2 - '/pivotx/includes/blogroll.php?color' Cross-Site Scripting
CVE-2011-0772—webappsphp25 ene 2011
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PivotX 2.2 - '/pivotx/includes/timwrapper.php?src' Cross-Site Scripting
CVE-2011-0772—webappsphp25 ene 2011
Multiple cross-site scripting (XSS) vulnerabilities in PivotX 2.2.0, and possibly other versions before 2.2.2, allow rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ActiveWeb Professional 3.0 - Arbitrary File Upload
CVE-2011-0678—webappscfm25 ene 2011
Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PivotX 2.2.2 - 'module_image.php' Cross-Site Scripting
CVE-2011-0773—webappsphp25 ene 2011
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Automated Solutions Modbus/TCP OPC Server - Remote Heap Corruption (PoC)
CVE-2010-4709—doswindows25 ene 2011
Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server - sp_replwritetovarbin Memory Corruption (MS09-004) (Metasploit)
CVE-2008-5416—remotewindows24 ene 2011
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin RSS Feed Reader 0.1 - 'rss_url' Cross-Site Scripting
CVE-2011-0740—webappsphp23 ene 2011
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allo
23RIESGO
abrir ↗
Exploit-DB
PHP Link Directory 4.1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2011-0643—webappsphp23 ene 2011
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows
23RIESGO
abrir ↗
Metasploit200
GoldenFTP PASS Stack Buffer Overflow
CVE-2006-6576—23 ene 2011
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow
CVE-2006-6576—remotewindows23 ene 2011
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java Web Start BasicServiceImpl - Remote Code Execution (Metasploit)
CVE-2010-3563—remotemultiple22 ene 2011
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote
60RIESGO
abrir ↗
Exploit-DB
Look n stop - Local Denial of Service
CVE-2011-0652—doswindows21 ene 2011
lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a denial of service (cras
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Server - Service Relative Path Stack Corruption (MS08-067) (Metasploit)
CVE-2008-4250CRITICALbajo ataqueremotewindows21 ene 2011
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpCMS 2008 - SQL Injection
CVE-2011-0645—webappsphp20 ene 2011
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CSS SetUserClip Memory Corruption (MS10-090) (Metasploit)
CVE-2010-3962HIGHbajo ataqueremotewindows20 ene 2011
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Lowbids - 'viewfaqs.php' Blind SQL Injection
CVE-2011-0646—webappsphp20 ene 2011
SQL injection vulnerability in viewfaqs.php in PHP LOW BIDS allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpCMS 2008 - SQL Injection
CVE-2011-0644—webappsphp20 ene 2011
SQL injection vulnerability in include/admin/model_field.class.php in PHPCMS 2008 V2 allows remote attackers to execute
23RIESGO
abrir ↗
← anteriorpágina 1239 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.