Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
Exploit-DB✓ VexDay Proof
Science Fair In A Box - SQL Injection / Cross-Site Scripting
CVE-2010-5026—webappsphp09 jun 2010
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HauntmAx CMS Haunted House - Directory Listing / SQL Injection
CVE-2010-2312—webappsphp09 jun 2010
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to exec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eLms Pro - SQL Injection / Cross-Site Scripting
CVE-2010-2356—webappsphp09 jun 2010
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Science Fair In A Box - SQL Injection / Cross-Site Scripting
CVE-2010-5027—webappsphp09 jun 2010
Cross-site scripting (XSS) vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote a
23RIESGO
abrir ↗
Metasploit600
Oracle BeeHive 2 voice-servlet processEvaluation() Vulnerability
CVE-2010-4417—09 jun 2010
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Online Notebook Manager - SQL Injection
CVE-2010-2342—webappsasp09 jun 2010
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eLms Pro - SQL Injection / Cross-Site Scripting
CVE-2010-2355—webappsphp09 jun 2010
Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arb
23RIESGO
abrir ↗
Metasploit600
Microsoft Help Center XSS and Command Execution
CVE-2010-1885—09 jun 2010
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash / Reader - Live Malware
CVE-2010-1297HIGHbajo ataqueremotemultiple09 jun 2010
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RIESGO
abrir ↗
Metasploit300
MS11-038 Microsoft Office Excel Malformed OBJ Record Handling Overflow
CVE-2010-0822—08 jun 2010
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RIESGO
abrir ↗
Metasploit500
HP OpenView Network Node Manager ovwebsnmpsrv.exe Unrecognized Option Buffer Overflow
CVE-2010-1960—08 jun 2010
Buffer overflow in the error handling functionality in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.5
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Home of MCLogin System - Authentication Bypass
CVE-2010-5000—webappsphp08 jun 2010
SQL injection vulnerability in login/login_index.php in MCLogin System 1.1 and 1.2 allows remote attackers to execute ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Audio Converter 8.1 - Local Stack Buffer Overflow
CVE-2010-2343—localwindows07 jun 2010
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Easy CD-DA Recorder 2007 - Local Buffer Overflow (SEH)
CVE-2010-2343—localwindows07 jun 2010
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir ↗
Metasploit300
Easy CD-DA Recorder PLS Buffer Overflow
CVE-2010-2343—07 jun 2010
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir ↗
Exploit-DB
CommonSense CMS - SQL Injection
CVE-2010-5037—webappsphp07 jun 2010
SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Audio Converter 8.1 - Local Stack Buffer Overflow ROP/WPM
CVE-2010-2343—localwindows07 jun 2010
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir ↗
Exploit-DB
idevspot Text ads 2.08 - SQL Injection
CVE-2010-2319—webappsphp06 jun 2010
SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CuteSITE CMS 1.x - '/manage/main.php?fld_path' Cross-Site Scripting
CVE-2010-5025—webappsphp06 jun 2010
Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to i
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component DJ-ArtGallery 0.9.1 - Multiple Vulnerabilities
CVE-2010-5042—webappsphp06 jun 2010
Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iScripts eSwap 2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-5035—webappsphp06 jun 2010
Cross-site scripting (XSS) vulnerability in search.php in iScripts eSwap 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB
iScripts easybiller 1.1 - SQL Injection
CVE-2010-5034—webappsphp06 jun 2010
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iScripts eSwap 2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-5036—webappsphp06 jun 2010
SQL injection vulnerability in addsale.php in iScripts eSwap 2.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Exploit-DB
Sphider Script - Remote Code Execution
CVE-2010-5044—webappsphp06 jun 2010
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remot
23RIESGO
abrir ↗
Exploit-DB
Joomla! Component Search Log 3.1.0 - SQL Injection
CVE-2010-5044—webappsphp06 jun 2010
SQL injection vulnerability in models/log.php in the Search Log (com_searchlog) component 3.1.0 for Joomla! allows remot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component DJ-ArtGallery 0.9.1 - Multiple Vulnerabilities
CVE-2010-5043—webappsphp06 jun 2010
SQL injection vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remote authentica
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CuteSITE CMS 1.x - '/manage/add_user.php?user_id' SQL Injection
CVE-2010-5024—webappsphp06 jun 2010
SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, wi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WmsCMS - Cross-Site Scripting / SQL Injection
CVE-2010-2316—webappsphp06 jun 2010
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to i
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WmsCMS - Cross-Site Scripting / SQL Injection
CVE-2010-2317—webappsphp06 jun 2010
Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WmsCMS - Cross-Site Scripting / SQL Injection
CVE-2007-3137—webappsphp06 jun 2010
Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to in
23RIESGO
abrir ↗
← anteriorpágina 1289 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.