Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
81.759 exploits
Exploit-DB✓ VexDay Proof
UCenter Home 2.0 - SQL Injection
CVE-2010-4912—webappsphp13 sep 2010
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kingsoft AntiVirus 2010.04.26.648 - Kernel Buffer Overflow
CVE-2010-3396—doswindows13 sep 2010
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Acrobat and Reader - 'pushstring' Memory Corruption
CVE-2010-2201—localwindows12 sep 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eshtery CMS - SQL Injection
CVE-2010-3404—webappsasp12 sep 2010
Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Word 2007 SP2 - sprmCMajority Buffer Overflow
CVE-2010-1900—doswindows11 sep 2010
Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Con
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Webkit (Apple Safari < 4.1.2/5.0.2 / Google Chrome < 5.0.375.125) - Memory Corruption
CVE-2010-1813—doswindows10 sep 2010
WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component Jphone 1.0 Alpha 3 - Local File Inclusion
CVE-2010-3426—webappsphp10 sep 2010
Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remo
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Excel RTD - Memory Corruption
CVE-2010-1247—localwindows10 sep 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Ex
28RIESGO
abrir ↗
Exploit-DB
symphony 2.0.7 - Multiple Vulnerabilities
CVE-2010-3458—webappsphp10 sep 2010
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attack
23RIESGO
abrir ↗
Exploit-DB
symphony 2.0.7 - Multiple Vulnerabilities
CVE-2010-3457—webappsphp10 sep 2010
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Datetopia Buy Dating Site - Cross-Site Scripting
CVE-2009-3355—webappsphp10 sep 2010
Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Excel RTD - Memory Corruption
CVE-2010-1246—localwindows10 sep 2010
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an
28RIESGO
abrir ↗
Exploit-DB
fcms 2.2.3 - Remote File Inclusion
CVE-2010-3419—webappsphp10 sep 2010
Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ES Simple Download 1.0. - Local File Inclusion
CVE-2010-3456—webappsphp09 sep 2010
Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
festos CMS 2.3b - Multiple Vulnerabilities
CVE-2010-4893—webappsphp09 sep 2010
Cross-site scripting (XSS) vulnerability in foodvendors.php in FestOS 2.3b allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.3 - XSLT Sort Remote Code Execution
CVE-2010-1199—doswindows09 sep 2010
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4,
28RIESGO
abrir ↗
Metasploit400
Audiotran PLS File Stack Buffer Overflow
CVE-2009-0476—09 sep 2010
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RIESGO
abrir ↗
Metasploit300
HP Data Protector DtbClsLogin Buffer Overflow
CVE-2010-3007—09 sep 2010
Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x befo
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Visio 2002 - '.DXF' Local Stack Overflow
CVE-2010-1681—localwindows08 sep 2010
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZenPhoto 1.3 - '/zp-core/admin.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-4907—webappsphp07 sep 2010
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ColdBookmarks 1.22 - SQL Injection
CVE-2010-4915—webappswindows07 sep 2010
SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Metasploit500
Race River Integard Home/Pro LoginAdmin Password Stack Buffer Overflow
CVE-2010-5333—07 sep 2010
The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long p
23RIESGO
abrir ↗
Metasploit500
Adobe CoolType SING Table "uniqueName" Stack Buffer Overflow
CVE-2010-2883HIGHbajo ataque07 sep 2010
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ColdCalendar 2.06 - SQL Injection
CVE-2010-4910—webappswindows07 sep 2010
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
1024 CMS 2.1.1 - Blind SQL Injection
CVE-2010-1093—webappsphp07 sep 2010
SQL injection vulnerability in rss.php in 1024 CMS 2.1.1, when magic_quotes_gpc is disabled, allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ColdUserGroup 1.06 - Blind SQL Injection
CVE-2010-4913—webappswindows07 sep 2010
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ColdUserGroup 1.06 - Blind SQL Injection
CVE-2010-4916—webappswindows07 sep 2010
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZenPhoto 1.3 - '/zp-core/full-image.php?a' SQL Injection
CVE-2010-4906—webappsphp07 sep 2010
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arb
23RIESGO
abrir ↗
Metasploit500
Adobe CoolType SING Table "uniqueName" Stack Buffer Overflow
CVE-2010-2883HIGHbajo ataque07 sep 2010
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Internet Download Accelerator 5.8 - Remote Buffer Overflow (PoC)
CVE-2007-3162—doswindows07 sep 2010
Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Ac
23RIESGO
abrir ↗
← anteriorpágina 1266 / 2726siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.