Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
CVE-2010-4347—locallinux18 dic 2010
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mafia Game Script - SQL Injection
CVE-2010-4619—webappsphp18 dic 2010
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Projekt Shop - 'details.php' Multiple SQL Injections
CVE-2010-4845—webappsphp18 dic 2010
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
CVE-2011-1021—locallinux18 dic 2010
drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by
23RIESGO
abrir ↗
Exploit-DB
Radius Manager 3.8.0 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-4275—webappsphp17 dic 2010
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-4275—webappsphp17 dic 2010
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k Pointer Dereferencement (PoC) (MS10-098)
CVE-2010-3944—doswindows_x8617 dic 2010
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Immo Makler Script - SQL Injection
CVE-2010-4721—webappsphp17 dic 2010
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MHP Downloadshop - SQL Injection
CVE-2010-4847—webappsphp17 dic 2010
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Easy Online Shop - SQL Injection
CVE-2010-4844—webappsphp17 dic 2010
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
CVE-2010-4345HIGHbajo ataqueremotelinux16 dic 2010
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specif
91RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Altap Salamander 2.5 PE Viewer - Local Buffer Overflow (Metasploit)
CVE-2007-3314—localwindows16 dic 2010
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (Englis
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe PDF - Embedded EXE Social Engineering (Metasploit)
CVE-2010-1240—localwindows16 dic 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JRadio - Local File Inclusion
CVE-2010-4719—webappsphp16 dic 2010
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to r
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)
CVE-2010-1240—localwindows16 dic 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
CVE-2010-4344CRITICALbajo ataqueremotelinux16 dic 2010
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RIESGO
abrir ↗
Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
CVE-2010-4749—webappsphp15 dic 2010
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB
Pointter PHP Micro-Blogging Social Network - Unauthorized Privilege Escalation
CVE-2010-4333—webappsphp15 dic 2010
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
CVE-2010-4604—locallinux15 dic 2010
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java - 'Statement.invoke()' Trusted Method Chain (Metasploit)
CVE-2010-0840CRITICALbajo ataqueremotemultiple15 dic 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RIESGO
abrir ↗
Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
CVE-2010-4348—webappsphp15 dic 2010
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attacker
23RIESGO
abrir ↗
Exploit-DB
Pointter PHP Content Management System - Unauthorized Privilege Escalation
CVE-2010-4332—webappsphp15 dic 2010
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
CVE-2010-4111—webappsphp15 dic 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RIESGO
abrir ↗
Exploit-DB
BEdita 3.0.1.2550 - Multiple Vulnerabilities
CVE-2010-5315—webappsphp15 dic 2010
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the aut
23RIESGO
abrir ↗
Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
CVE-2010-4349—webappsphp15 dic 2010
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an inv
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser
CVE-2010-3971—remotewindows15 dic 2010
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir ↗
Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
CVE-2010-4750—webappsphp15 dic 2010
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allow
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
gitWeb 1.7.3.3 - Cross-Site Scripting
CVE-2010-3906—webappscgi15 dic 2010
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Local File Inclusion
CVE-2010-4350—webappsphp15 dic 2010
Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to in
23RIESGO
abrir ↗
Metasploit500
MS11-006 Microsoft Windows CreateSizedDIBSECTION Stack Buffer Overflow
CVE-2010-3970—15 dic 2010
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RIESGO
abrir ↗
← anteriorpágina 1244 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.