Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.858exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
Exploit-DB✓ VexDay Proof
Media Player Classic 6.4.9.1 - 'iacenc.dll' DLL Hijacking
CVE-2010-3138—localwindows25 ago 2010
Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft RRAS Service - RASMAN Registry Overflow (MS06-025) (Metasploit)
CVE-2006-2370—remotewindows25 ago 2010
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RIESGO
abrir ↗
Exploit-DB
Foxit Reader 4.0 - '.pdf' Multiple Stack Based Buffer Overflow 'Jailbreak'
CVE-2010-1797—localwindows24 ago 2010
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpr
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.8 - 'dwmapi.dll' DLL Hijacking
CVE-2010-3131—localwindows24 ago 2010
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RIESGO
abrir ↗
Exploit-DB
Microsoft PowerPoint 2010 - 'pptimpconv.dll' DLL Hijacking
CVE-2010-3142—localwindows24 ago 2010
Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attacker
28RIESGO
abrir ↗
Exploit-DB
Microsoft Windows 7 - 'wab32res.dll wab.exe' DLL Hijacking
CVE-2010-3143—localwindows24 ago 2010
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RIESGO
abrir ↗
Exploit-DB
Microsoft Windows Movie Maker 2.6.4038.0 - 'hhctrl.ocx' DLL Hijacking
CVE-2010-3967—localwindows24 ago 2010
Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via
28RIESGO
abrir ↗
Exploit-DB
Microsoft Windows 7 - 'wab32res.dll wab.exe' DLL Hijacking
CVE-2010-3147—localwindows24 ago 2010
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark 1.2.10 - 'airpcap.dll' DLL Hijacking
CVE-2010-3133—localwindows24 ago 2010
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and p
23RIESGO
abrir ↗
Exploit-DB
Microsoft PowerPoint 2010 - 'pptimpconv.dll' DLL Hijacking
CVE-2010-3141—localwindows24 ago 2010
Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to e
28RIESGO
abrir ↗
Exploit-DB
TeamViewer 5.0.8703 - 'dwmapi.dll' DLL Hijacking
CVE-2010-3128—localwindows24 ago 2010
Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers
23RIESGO
abrir ↗
Exploit-DB
Adobe Dreamweaver CS4 - 'ibfs32.dll' DLL Hijacking
CVE-2010-3132—localwindows24 ago 2010
Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera 10.61 - 'dwmapi.dll' DLL Hijacking
CVE-2010-5227—localwindows24 ago 2010
Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmap
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
μTorrent (uTorrent) 2.0.3 - 'plugin_dll.dll' DLL Hijacking
CVE-2010-3129—localwindows24 ago 2010
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Auto CMS 1.6 - 'autocms.php' Cross-Site Scripting
CVE-2010-4882—webappsphp23 ago 2010
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MicroP 0.1.1.1600 - 'mppl' Local Buffer Overflow
CVE-2010-5299—localwindows23 ago 2010
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir ↗
Metasploit500
MicroP 0.1.1.1600 (MPPL File) Stack Buffer Overflow
CVE-2010-5299—23 ago 2010
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir ↗
Exploit-DB
Microsoft Excel - FEATHEADER Record (MS09-067)
CVE-2009-3129HIGHbajo ataquelocalwindows21 ago 2010
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle MySQL < 5.1.49 - Malformed 'BINLOG' Arguments Denial of Service
CVE-2010-3679—doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via
28RIESGO
abrir ↗
Exploit-DB
Microsoft Word - Record Parsing Buffer Overflow (MS09-027)
CVE-2009-0565—localwindows20 ago 2010
Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 200
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OraclMySQL 5.1.48 - 'LOAD DATA INFILE' Denial of Service
CVE-2010-3683—doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL err
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL 5.1.48 - 'EXPLAIN' Denial of Service
CVE-2010-3682—doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mys
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle MySQL 5.1.48 - 'HANDLER' Interface Denial of Service
CVE-2010-3681—doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysq
28RIESGO
abrir ↗
Metasploit300
Novell iPrint Client ActiveX Control call-back-url Buffer Overflow
CVE-2010-1527—20 ago 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL 5.1.48 - 'Temporary InnoDB' Tables Denial of Service
CVE-2010-3680—dosphp19 ago 2010
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by c
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Flock Browser 3.0.0 - Malformed Bookmark HTML Injection
CVE-2010-3202—remotemultiple19 ago 2010
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cacti 0.8.7 (RedHat High Performance Computing [HPC]) - 'utilities.php?Filter' Cross-Site Scripting
CVE-2010-2544—webappsphp19 ago 2010
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD - 'mbufs()' sendfile Cache Poisoning Privilege Escalation
CVE-2010-2693—localfreebsd19 ago 2010
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, whi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)
CVE-2007-2447—remoteunix18 ago 2010
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050)
CVE-2009-3103—remotewindows17 ago 2010
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir ↗
← anteriorpágina 1272 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.