Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
82.004 exploits
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
CVE-2009-4178—remotewindows30 mar 2010
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows rem
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow
CVE-2009-1642—localwindows30 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
CVE-2010-2335—webappsphp30 mar 2010
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RIESGO
abrir ↗
Metasploit500
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
CVE-2010-0842—30 mar 2010
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Shadow Stream Recorder 3.0.1.7 - '.asx' Local Buffer Overflow
CVE-2009-1642—localwindows30 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
CVE-2010-1309—webappsphp30 mar 2010
Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary
23RIESGO
abrir ↗
Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
CVE-2010-1300—webappsphp30 mar 2010
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' (PoC)
CVE-2011-5165—doswindows30 mar 2010
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
CVE-2008-7254—webappsphp30 mar 2010
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, w
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Easy-Clanpage 2.1 - SQL Injection
CVE-2008-1425—webappsmultiple30 mar 2010
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir ↗
Metasploit600
Novell ZENworks Configuration Management Remote Execution
CVE-2010-5324—30 mar 2010
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration M
60RIESGO
abrir ↗
Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x21 Buffer Overflow
CVE-2012-2215—30 mar 2010
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RIESGO
abrir ↗
Metasploit300
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
CVE-2009-1641—29 mar 2010
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_weblinks - 'id' SQL Injection
CVE-2010-2679—webappsphp29 mar 2010
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbit
23RIESGO
abrir ↗
Metasploit600
Adobe PDF Embedded EXE Social Engineering
CVE-2010-1240—29 mar 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
Metasploit600
Adobe PDF Escape EXE Social Engineering (No JavaScript)
CVE-2010-1240—29 mar 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
CVE-2009-1642—doswindows29 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-2675—webappsphp28 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Devana - SQL Injection
CVE-2010-2673—webappsphp28 mar 2010
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
CVE-2010-1270—webappsphp28 mar 2010
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-2674—webappsphp28 mar 2010
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
CVE-2010-1269—webappsphp28 mar 2010
SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Uebimiau Webmail 2.7.2 - Multiple Vulnerabilities
CVE-2007-5235—webappsphp27 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
CVE-2010-2677—webappsphp27 mar 2010
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is dis
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
CVE-2010-2676—webappsphp27 mar 2010
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP MaxDB - Malformed Handshake Request Remote Code Execution
CVE-2010-1185—remotewindows26 mar 2010
Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to ex
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iOS Safari - Bad 'VML' Remote Denial of Service
CVE-2010-1179—dosios26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
UoW IMAPd Server - LSUB Buffer Overflow (Metasploit)
CVE-2000-0284—remotelinux26 mar 2010
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iOS Safari - Remote Denial of Service
CVE-2010-1176—dosios26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari for iPhone/iPod touch - 'Throw' Exception Remote Code Execution
CVE-2010-1180—remoteosx26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
← anteriorpágina 1310 / 2734siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.