Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
81.924 exploits
Metasploit600
Adobe PDF Embedded EXE Social Engineering
CVE-2010-1240—29 mar 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
Metasploit300
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
CVE-2009-1641—29 mar 2010
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_weblinks - 'id' SQL Injection
CVE-2010-2679—webappsphp29 mar 2010
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
CVE-2009-1642—doswindows29 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
CVE-2010-1270—webappsphp28 mar 2010
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
CVE-2010-1269—webappsphp28 mar 2010
SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-2674—webappsphp28 mar 2010
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-2675—webappsphp28 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Devana - SQL Injection
CVE-2010-2673—webappsphp28 mar 2010
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
CVE-2010-2676—webappsphp27 mar 2010
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
CVE-2010-2677—webappsphp27 mar 2010
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is dis
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Uebimiau Webmail 2.7.2 - Multiple Vulnerabilities
CVE-2007-5235—webappsphp27 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component dcsFlashGames 2.0RC1 - 'catid' SQL Injection
CVE-2010-1265—webappsphp26 mar 2010
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari for iPhone/iPod touch - 'Throw' Exception Remote Code Execution
CVE-2010-1180—remoteosx26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iOS Safari - Bad 'VML' Remote Denial of Service
CVE-2010-1179—dosios26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UoW IMAPd Server - LSUB Buffer Overflow (Metasploit)
CVE-2000-0284—remotelinux26 mar 2010
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iOS Safari - Remote Denial of Service
CVE-2010-1176—dosios26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP MaxDB - Malformed Handshake Request Remote Code Execution
CVE-2010-1185—remotewindows26 mar 2010
Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to ex
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari iPhone/iPod touch - Webpage Remote Code Execution
CVE-2010-1177—remoteosx26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
justVisual 2.0 - 'index.php' Local File Inclusion
CVE-2010-1268—webappsphp25 mar 2010
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
INVOhost - SQL Injection
CVE-2010-1336—webappsphp25 mar 2010
Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco TFTP Server 1.1 - Denial of Service
CVE-2010-1174—doswindows25 mar 2010
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SiteX CMS 0.7.4 Beta - 'photo.php' SQL Injection
CVE-2010-1343—webappsphp25 mar 2010
SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Direct News 4.10.2 - Multiple Remote File Inclusions
CVE-2010-1342—webappsphp25 mar 2010
Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lexmark Multiple Laser printers - Remote Stack Overflow
CVE-2010-0619—doshardware25 mar 2010
Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE componen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6 - 'gfxTextRun::SanitizeGlyphRuns()' Remote Memory Corruption
CVE-2010-0166—dosmultiple24 mar 2010
The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 be
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Connection Update Manager for Solaris - Multiple Insecure Temporary File Creation Vulnerabilities
CVE-2010-1183—localsolaris24 mar 2010
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_jresearch - 'Controller' Local File Inclusion
CVE-2010-1340—webappsphp24 mar 2010
Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple Memory Corruption Vulnerabilities
CVE-2010-0167—doslinux24 mar 2010
The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird befor
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Insky CMS 006-0111 - Multiple Remote File Inclusions
CVE-2010-1335—webappsphp23 mar 2010
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RIESGO
abrir ↗
← anteriorpágina 1309 / 2731siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.