Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
81.759 exploits
Exploit-DB✓ VexDay Proof
SlimFTPd - 'LIST' Concatenation Overflow (Metasploit)
CVE-2005-2373—remotewindows05 oct 2010
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directo
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - Remote Overflow (Metasploit)
CVE-2002-1120—remotewindows04 oct 2010
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Surgemail SurgeWeb 4.3e - Cross-Site Scripting
CVE-2010-3201—webappsphp04 oct 2010
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DNET Live-Stats 0.8 - Local File Inclusion
CVE-2010-4858—webappsphp04 oct 2010
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD - 'pseudofs' Null Pointer Dereference Privilege Escalation
CVE-2010-4210—localbsd04 oct 2010
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previo
23RIESGO
abrir ↗
Metasploit200
CA BrightStor ARCserve Tape Engine 0x8A Buffer Overflow
CVE-2006-6076—04 oct 2010
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting
CVE-2010-3425—webappsasp02 oct 2010
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SmarterMail < 7.2.3925 - LDAP Injection
CVE-2010-3486—webappsasp02 oct 2010
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 6.0 - ASP Stack Overflow Stack Exhaustion (Denial of Service) (MS10-065)
CVE-2010-1899—doswindows01 oct 2010
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection
CVE-2010-4866—webappsphp01 oct 2010
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Trend Micro Internet Security Pro 2010 - ActiveX 'extSetOwner()' Remote Code Execution (Metasploit)
CVE-2010-3189—remotewindows01 oct 2010
The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Unicode Scripts Processor - Remote Code Execution (MS10-063)
CVE-2010-2738—doswindows30 sep 2010
The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
CVE-2010-4865—webappsphp30 sep 2010
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Directory 1.0 - SQL Injection
CVE-2010-4862—webappsphp30 sep 2010
SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Excel - SxView Record Parsing Heap Memory Corruption
CVE-2010-1245—doswindows29 sep 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML Fil
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Webspell 4.2.1 - 'asearch.php' SQL Injection
CVE-2010-4861—webappsphp29 sep 2010
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MODx manager - '/controllers/default/resource/tvs.php?class_key' Traversal Local File Inclusion
CVE-2010-5278—webappsphp29 sep 2010
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possi
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MyPhpAuction 2010 - 'id' SQL Injection
CVE-2010-4860—webappsphp29 sep 2010
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XFS - Deleted Inode Local Information Disclosure
CVE-2010-2943—locallinux29 sep 2010
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode b
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Getsimple CMS 2.01 - 'changedata.php' Cross-Site Scripting
CVE-2010-4863—webappsphp29 sep 2010
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MODx 2.0.2-pl - '/manager/index.php?modahsh' Cross-Site Scripting
CVE-2010-4883—webappsphp29 sep 2010
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc6 (RedHat / Ubuntu 10.04) - 'pktcdvd' Kernel Memory Disclosure
CVE-2010-3437—locallinux29 sep 2010
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
CVE-2007-1748—remotewindows28 sep 2010
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'Winhlp32.exe' MsgBox Code Execution (MS10-023) (Metasploit)
CVE-2010-0483—remotewindows28 sep 2010
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPMyFAQ 2.6.x - 'index.php' Cross-Site Scripting
CVE-2010-4821—webappsphp28 sep 2010
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Horde IMP Webmail 4.3.7 - 'fetchmailprefs.php' HTML Injection
CVE-2010-3695—webappsphp27 sep 2010
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Ed
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML Findtext Processing
CVE-2010-2553—doswindows27 sep 2010
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Entrans - SQL Injection
CVE-2010-4935—webappsphp27 sep 2010
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Exploit-DB
Allpc 2.5 osCommerce - SQL Injection / Cross-Site Scripting
CVE-2010-4947—webappswindows_x8627 sep 2010
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in ALLPC 2.5 allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
CVE-2010-0094—remotemultiple27 sep 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RIESGO
abrir ↗
← anteriorpágina 1259 / 2726siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.