Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
Exploit-DB✓ VexDay Proof
Yamamah Photo Gallery 1.00 - 'download.php' Local File Disclosure
CVE-2010-2334—webappsphp13 jun 2010
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yamamah 1.0 - SQL Injection
CVE-2010-1300—webappsphp12 jun 2010
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BrightSuite Groupware - SQL Injection
CVE-2010-5008—webappsasp12 jun 2010
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RIESGO
abrir ↗
Metasploit600
UnrealIRCD 3.2.8.1 Backdoor Command Execution
CVE-2010-2075—12 jun 2010
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VU Web Visitor Analyst - Authentication Bypass
CVE-2010-2338—webappsasp12 jun 2010
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
CVE-2010-2336—webappsphp12 jun 2010
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SolarWinds TFTP Server 10.4.0.13 - Denial of Service
CVE-2010-2310—doswindows12 jun 2010
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.
28RIESGO
abrir ↗
Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
CVE-2010-2335—webappsphp12 jun 2010
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RIESGO
abrir ↗
Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
CVE-2010-2334—webappsphp12 jun 2010
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RIESGO
abrir ↗
Exploit-DB
Yamamah - 'news' SQL Injection / Source Code Disclosure
CVE-2010-1300—webappsphp12 jun 2010
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB
ardeacore 2.2 - Remote File Inclusion
CVE-2010-4998—webappsphp11 jun 2010
PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Streamcast 0.9.75 - HTTP User-Agent Buffer Overflow (Metasploit)
CVE-2008-0550—remotewindows11 jun 2010
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AneCMS 1.x - '/modules/blog/index.php' SQL Injection
CVE-2010-2436—webappsphp11 jun 2010
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB
DaLogin - Multiple Vulnerabilities
CVE-2010-5012—webappsphp11 jun 2010
SQL injection vulnerability in new.php in DaLogin 2.2 and 2.2.5 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nginx 0.7.65/0.8.39 (dev) - Source Disclosure / Download
CVE-2010-2263—remotewindows11 jun 2010
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Power Tab Editor 1.7 (Build 80) - Local Buffer Overflow
CVE-2010-2311—localwindows11 jun 2010
Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sygate Personal Firewall 5.6 build 2808 - ActiveX with DEP Bypass
CVE-2010-2305—remotewindows11 jun 2010
Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nginx 0.8.36 - Source Disclosure / Denial of Service
CVE-2010-2263—remotewindows11 jun 2010
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AneCMS 1.x - '/modules/blog/index.php' HTML Injection
CVE-2010-2437—webappsphp11 jun 2010
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nginx 0.8.36 - Source Disclosure / Denial of Service
CVE-2010-2266—remotewindows11 jun 2010
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequen
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe InDesign CS3 - '.INDD' Handling Buffer Overflow
CVE-2010-2321—doswindows11 jun 2010
Buffer overflow in Adobe InDesign CS3 10.0 allows user-assisted remote attackers to execute arbitrary code via a crafted
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Help and Support Center - '/sysinfo/sysinfomain.htm' Cross-Site Scripting
CVE-2010-2265—remotewindows10 jun 2010
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Hel
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Help Centre Handles - Malformed Escape Sequences Incorrectly (MS03-044)
CVE-2010-1885—remotewindows10 jun 2010
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SchoolMation 2.3 - SQL Injection / Cross-Site Scripting
CVE-2010-5011—webappsphp10 jun 2010
SQL injection vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SchoolMation 2.3 - SQL Injection / Cross-Site Scripting
CVE-2010-5010—webappsphp10 jun 2010
Cross-site scripting (XSS) vulnerability in schoolmv2/html/studentmain.php in SchoolMation 2.3 allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB
Netvolution CMS 2.x - SQL Injection Script
CVE-2010-4967—webappsasp10 jun 2010
SQL injection vulnerability in default.asp in ATCOM Netvolution 2.5.6 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Arab Portal 2.2 - 'members.php' SQL Injection
CVE-2010-2340—webappsphp10 jun 2010
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir ↗
Metasploit600
Oracle BeeHive 2 voice-servlet processEvaluation() Vulnerability
CVE-2010-4417—09 jun 2010
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eLms Pro - SQL Injection / Cross-Site Scripting
CVE-2010-2356—webappsphp09 jun 2010
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Science Fair In A Box - SQL Injection / Cross-Site Scripting
CVE-2010-5026—webappsphp09 jun 2010
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RIESGO
abrir ↗
← anteriorpágina 1288 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.