Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
81.759 exploits
Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'custom.php?testmode' Cross-Site Scripting
CVE-2010-3003—webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mBlogger 1.0.04 - 'viewpost.php' SQL Injection
CVE-2010-4876—webappsphp31 ago 2010
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'parameters.php?device' Cross-Site Scripting
CVE-2010-3003—webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE FAQ Pro 1.5.0 - Multiple Blind SQL Injections
CVE-2010-3211—webappsphp31 ago 2010
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'globals.php?tabpage' Cross-Site Scripting
CVE-2010-3003—webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗
Exploit-DB
seagull 0.6.7 - Remote File Inclusion
CVE-2010-3209—webappsphp30 ago 2010
Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Plug and Play Service - Overflow (MS05-039) (Metasploit)
CVE-2005-1983—doswindows30 ago 2010
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime - '_Marshaled_pUnk' Backdoor Client-Side Arbitrary Code Execution
CVE-2010-1818—doswindows30 ago 2010
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component PicSell 1.0 - Local File Disclosure
CVE-2010-3203—webappsphp30 ago 2010
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read
38RIESGO
abrir ↗
Metasploit500
Apple QuickTime 7.6.7 _Marshaled_pUnk Code Execution
CVE-2010-1818—30 ago 2010
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RIESGO
abrir ↗
Exploit-DB
Multi-lingual E-Commerce System 0.2 - Multiple Remote File Inclusions
CVE-2010-3210—webappsphp29 ago 2010
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to exec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Seagull 0.6.7 - SQL Injection
CVE-2010-3212—webappsphp29 ago 2010
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nginx 0.6.38 - Heap Corruption
CVE-2009-2629—locallinux29 ago 2010
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, a
45RIESGO
abrir ↗
Exploit-DB
textpattern CMS 4.2.0 - Remote File Inclusion
CVE-2010-3205—webappsphp28 ago 2010
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GaleriaSHQIP 1.0 - SQL Injection
CVE-2010-3207—webappsphp28 ago 2010
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗
Exploit-DB
DIY-CMS 1.0 - Multiple Remote File Inclusions
CVE-2010-3206—webappsphp28 ago 2010
Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XOOPS 2.0.14 - 'article.php' SQL Injection
CVE-2008-2094—webappsphp28 ago 2010
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB
pecio CMS 2.0.5 - Multiple Remote File Inclusions
CVE-2010-3204—webappsphp27 ago 2010
Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iGaming CMS - Multiple SQL Injections
CVE-2008-5841—webappsphp27 ago 2010
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc1 (Ubuntu 10.04 / 2.6.32) - 'CAN BCM' Local Privilege Escalation
CVE-2010-2959—locallinux27 ago 2010
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
kontakt formular 1.1 - Remote File Inclusion
CVE-2010-4878—webappsphp26 ago 2010
PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Gaestebuch 1.2 - Remote File Inclusion
CVE-2010-4884—webappsphp26 ago 2010
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EncFS 1.6.0 - Flawed CBC/CFB Cryptography Implementation
CVE-2010-3073—locallinux26 ago 2010
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
μTorrent (uTorrent) 2.0.3 - DLL Hijacking
CVE-2010-3129—localwindows25 ago 2010
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xitami Web Server 2.5c2 - If-Modified-Since Overflow (Metasploit)
CVE-2007-5067—remotewindows25 ago 2010
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Skype 4.2.0.169 - 'wab32.dll' DLL Hijacking
CVE-2010-3136—localwindows25 ago 2010
Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - Contacts 'wab32res.dll' DLL Hijacking
CVE-2010-3143—localwindows25 ago 2010
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RIESGO
abrir ↗
Exploit-DB
Adobe Illustrator CS4 - 'aires.dll' DLL Hijacking
CVE-2010-3152—localwindows25 ago 2010
Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Thunderbird - 'dwmapi.dll' DLL Hijacking
CVE-2010-3131—localwindows25 ago 2010
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RIESGO
abrir ↗
Exploit-DB
Microsoft Office Groove 2007 - 'mso.dll' DLL Hijacking
CVE-2010-3146—localwindows25 ago 2010
Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a T
28RIESGO
abrir ↗
← anteriorpágina 1268 / 2726siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.