Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
Exploit-DB✓ VexDay Proof
Apple Mac OSX EvoCam Web Server 3.6.6/3.6.7 - Remote Buffer Overflow
CVE-2010-2309—remoteosx05 jun 2010
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RIESGO
abrir ↗
Metasploit300
Adobe Flash Player "newfunction" Invalid Pointer Use
CVE-2010-1297HIGHbajo ataque04 jun 2010
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RIESGO
abrir ↗
Metasploit300
Adobe Flash Player "newfunction" Invalid Pointer Use
CVE-2010-1297HIGHbajo ataque04 jun 2010
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RIESGO
abrir ↗
Exploit-DB
phpBazar 2.1.1 stable - Remote File Inclusion
CVE-2010-2315—webappsphp03 jun 2010
PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execut
23RIESGO
abrir ↗
Exploit-DB
Motorola Surfboard Cable Modem - Directory Traversal
CVE-2010-2307—remotehardware03 jun 2010
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmw
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SIMM Management System (SMS) - Local File Inclusion
CVE-2010-2313—webappsphp02 jun 2010
Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_qu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TCExam 10.1.7 - '/admin/code/tce_functions_tcecode_editor.php' Arbitrary File Upload
CVE-2010-2153—webappsphp02 jun 2010
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 al
23RIESGO
abrir ↗
Metasploit600
Outlook ATTACH_BY_REF_RESOLVE File Execution
CVE-2010-0266—01 jun 2010
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_
50RIESGO
abrir ↗
Metasploit600
Outlook ATTACH_BY_REF_ONLY File Execution
CVE-2010-0266—01 jun 2010
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_
50RIESGO
abrir ↗
Metasploit200
MacOS X EvoCam HTTP GET Buffer Overflow
CVE-2010-2309—01 jun 2010
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DM Database Server - 'SP_DEL_BAK_EXPIRED' Memory Corruption
CVE-2010-2159—dosmultiple31 may 2010
Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute ar
23RIESGO
abrir ↗
Exploit-DB
Joomla! Component JS Jobs 1.0.5.8 - SQL Injection
CVE-2009-4599—webappsphp31 may 2010
Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Visitor Logger - 'banned.php' Remote File Inclusion
CVE-2010-2146—webappsphp31 may 2010
PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symphony CMS - Local File Inclusion
CVE-2010-2143—webappsphp30 may 2010
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CMScout - Cross-Site Scripting / HTML Injection
CVE-2010-2154—webappsphp30 may 2010
Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Zeeways Script - Multiple Vulnerabilities
CVE-2010-2144—webappsphp30 may 2010
Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component BF Quiz 1.0 - SQL Injection (2)
CVE-2010-5032—webappsphp29 may 2010
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nucleus Plugin Gallery - Remote File Inclusion / SQL Injection
CVE-2010-5041—webappsphp29 may 2010
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nucleus Plugin Gallery - Remote File Inclusion / SQL Injection
CVE-2010-5040—webappsphp29 may 2010
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
fusebox - 'ProductList.cfm?CatDisplay' SQL Injection
CVE-2010-5033—webappswindows29 may 2010
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB
Nucleus Plugin Twitter - Remote File Inclusion
CVE-2010-2314—webappsphp29 may 2010
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucle
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component My Car 1.0 - Multiple Vulnerabilities
CVE-2010-2148—webappsphp28 may 2010
SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Job 1.0 - 'catid' SQL Injection
CVE-2010-5028—webappsphp28 may 2010
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to e
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component My Car 1.0 - Multiple Vulnerabilities
CVE-2010-2147—webappsphp28 may 2010
Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component BF Quiz 1.3.0 - SQL Injection (1)
CVE-2010-5032—webappsphp28 may 2010
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 8.0 - 'ftpd' (FreeBSD-SA-10:05) Off-By-One (PoC)
CVE-2010-1938—dosfreebsd27 may 2010
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.ABR' File Handling Remote Buffer Overflow (PoC)
CVE-2010-1296—doswindows26 may 2010
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Worldweaver DX Studio Player 3.0.29 - 'shell.execute()' Command Execution (Metasploit)
CVE-2009-2011—remotewindows26 may 2010
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.ASL' File Handling Remote Buffer Overflow (PoC)
CVE-2010-1296—doswindows26 may 2010
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.GRD' File Handling Remote Buffer Overflow (PoC)
CVE-2010-1296—doswindows26 may 2010
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RIESGO
abrir ↗
← anteriorpágina 1290 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.