Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
81.859 exploits
Exploit-DB✓ VexDay Proof
Shopzilla Affiliate Script PHP - 'search.php' Cross-Site Scripting
CVE-2010-2040—webappsphp19 may 2010
Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Palo Alto Network Vulnerability - Cross-Site Scripting
CVE-2010-0475—webappshardware19 may 2010
Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JComments 2.1 - 'ComntrNam' Cross-Site Scripting
CVE-2010-5048—webappsphp18 may 2010
Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
gpEasy CMS 1.6.2 - 'editing_files.php' Cross-Site Scripting
CVE-2010-2038—webappsphp18 may 2010
Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticat
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lokomedia CMS - 'sukaCMS' Local File Disclosure
CVE-2010-2018—webappsphp18 may 2010
Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrar
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Btrfs Cloned File Security Bypass
CVE-2010-1636—locallinux18 may 2010
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ecoCMS 18.4.2010 - 'admin.php' Cross-Site Scripting
CVE-2010-5046—webappsphp18 may 2010
Cross-site scripting (XSS) vulnerability in admin.php in ecoCMS allows remote attackers to inject arbitrary web script o
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
JE CMS 1.1 - SQL Injection
CVE-2010-2047—webappsphp17 may 2010
SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
The iceberg - 'Content Management System' SQL Injection
CVE-2010-2016—webappsphp16 may 2010
SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component simpledownload 0.9.5 - Local File Disclosure
CVE-2010-2122—webappsphp16 may 2010
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows r
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component simpledownload 0.9.5 - Local File Inclusion
CVE-2010-2122—webappsphp16 may 2010
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows r
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component MS Comment 0.8.0b - Local File Inclusion
CVE-2010-2050—webappsphp15 may 2010
Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari 4.0.5 - 'parent.close()' Memory Corruption (ASLR + DEP Bypass)
CVE-2010-1939—remotewindows15 may 2010
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion
CVE-2010-2128—webappsphp14 may 2010
Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote a
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - 'RETR' Denial of Service (1)
CVE-2005-3294—doswindows14 may 2010
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IncrediMail - 'ImShExtU.dll' ActiveX Memory Corruption
CVE-2007-1683—doswindows14 may 2010
Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.d
35RIESGO
abrir ↗
Exploit-DB
Press Release Script - 'page.php?id' SQL Injection
CVE-2010-5047—webappsphp14 may 2010
SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.3.x < 5.3.2 - 'ext/phar/stream.c' / 'ext/phar/dirstream.c' Multiple Format String Vulnerabilities
CVE-2010-2094—remotephp14 may 2010
Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
JE Ajax Event Calendar - Local File Inclusion
CVE-2010-2129—webappsphp14 may 2010
Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Job 1.0 - Local File Inclusion
CVE-2010-5028—webappsphp14 may 2010
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to e
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VMware View Portal 3.1 - Cross-Site Scripting
CVE-2010-1143—webappsmultiple14 may 2010
Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 bui
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion
CVE-2010-2045—webappsphp13 may 2010
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component Komento 1.0.0 - 'sid' SQL Injection
CVE-2010-2044—webappsphp13 may 2010
SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to ex
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Alert Management System Intel Alert Originator Service - Remote Buffer Overflow (Metasploit)
CVE-2009-1430—remotewindows13 may 2010
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management Syst
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Shockwave Player 11.5.6.606 - 'DIR' Multiple Memory Vulnerabilities
CVE-2010-1280—doswindows12 may 2010
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TomatoCMS 2.0.x - SQL Injection
CVE-2010-1994—webappsphp12 may 2010
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
CVE-2010-0816—doswindows11 may 2010
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2
28RIESGO
abrir ↗
Metasploit500
HP OpenView Network Node Manager getnnmdata.exe (MaxAge) CGI Buffer Overflow
CVE-2010-1553—11 may 2010
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
60RIESGO
abrir ↗
Metasploit500
HP OpenView Network Node Manager getnnmdata.exe (Hostname) CGI Buffer Overflow
CVE-2010-1555—11 may 2010
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AgentX++ Master - AgentX::receive_agentx Stack Buffer Overflow (Metasploit)
CVE-2010-1318—remotewindows11 may 2010
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Ser
50RIESGO
abrir ↗
← anteriorpágina 1292 / 2729siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.