Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
82.004 exploits
Exploit-DB✓ VexDay Proof
Apple Safari for iPhone/iPod touch - 'Throw' Exception Remote Code Execution
CVE-2010-1180—remoteosx26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari iPhone/iPod touch - Webpage Remote Code Execution
CVE-2010-1177—remoteosx26 mar 2010
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco TFTP Server 1.1 - Denial of Service
CVE-2010-1174—doswindows25 mar 2010
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
justVisual 2.0 - 'index.php' Local File Inclusion
CVE-2010-1268—webappsphp25 mar 2010
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lexmark Multiple Laser printers - Remote Stack Overflow
CVE-2010-0619—doshardware25 mar 2010
Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE componen
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
INVOhost - SQL Injection
CVE-2010-1336—webappsphp25 mar 2010
Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SiteX CMS 0.7.4 Beta - 'photo.php' SQL Injection
CVE-2010-1343—webappsphp25 mar 2010
SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Direct News 4.10.2 - Multiple Remote File Inclusions
CVE-2010-1342—webappsphp25 mar 2010
Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_jresearch - 'Controller' Local File Inclusion
CVE-2010-1340—webappsphp24 mar 2010
Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6 - 'gfxTextRun::SanitizeGlyphRuns()' Remote Memory Corruption
CVE-2010-0166—dosmultiple24 mar 2010
The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 be
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple Memory Corruption Vulnerabilities
CVE-2010-0167—doslinux24 mar 2010
The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird befor
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Connection Update Manager for Solaris - Multiple Insecure Temporary File Creation Vulnerabilities
CVE-2010-1183—localsolaris24 mar 2010
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SpringSource (Multiple Products) - Multiple HTML Injection Vulnerabilities
CVE-2009-2907—webappsphp23 mar 2010
Multiple cross-site scripting (XSS) vulnerabilities in SpringSource tc Server 6.0.20.B and earlier, Application Manageme
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RepairShop2 - 'index.php?Prod' Cross-Site Scripting
CVE-2010-1856—webappsphp23 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component Property - Local File Inclusion
CVE-2010-1875—webappsphp23 mar 2010
Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows re
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Insky CMS 006-0111 - Multiple Remote File Inclusions
CVE-2010-1335—webappsphp23 mar 2010
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lussumo Vanilla 1.1.10 - 'definitions.php' Multiple Remote File Inclusions
CVE-2010-1337—webappsphp23 mar 2010
Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component SMEStorage - Local File Inclusion
CVE-2010-1858—webappsphp23 mar 2010
Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote atta
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Uiga Fan Club - SQL Injection
CVE-2010-1365—webappsphp22 mar 2010
SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mini-CMS RibaFS 1.0 - Authentication Bypass
CVE-2010-1346—webappsphp22 mar 2010
SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Safari 4.0.5 - Object Tag 'JavaScriptCore.dll' Crash (Denial of Service)
CVE-2010-1131—doswindows22 mar 2010
JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote attackers to cause a denial of servic
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebMaid CMS 0.2-6 Beta - Multiple Remote File Inclusions
CVE-2010-1266—webappsphp21 mar 2010
Multiple PHP remote file inclusion vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to execu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebMaid CMS 0.2-6 Beta - Multiple Remote File Inclusions
CVE-2010-1267—webappsphp21 mar 2010
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NotSopureEdit 1.4.1 - Remote File Inclusion
CVE-2010-1216—webappsphp21 mar 2010
PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_glob
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Woltlab Burning Board Teamsite Hack 3.0 - 'ts_other.php' SQL Injection
CVE-2010-1338—webappsphp21 mar 2010
SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pay Per Watch & Bid Auktions System - 'auktion.php?id_auk' Blind SQL Injection
CVE-2010-1855—webappsphp20 mar 2010
SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component & Plugin JE Tooltip 1.0 - Local File Inclusion
CVE-2010-1217—webappsphp19 mar 2010
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is
38RIESGO
abrir ↗
Metasploit400
Steinberg MyMP3Player 3.0 Buffer Overflow
CVE-2010-20123HIGH18 mar 2010
Steinberg MyMP3Player <= 3.0.0.67 Buffer Overflow
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpscripte24 Niedrig Gebote Pro Auktions System II - Blind SQL Injection
CVE-2010-1270—webappsphp18 mar 2010
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6 - Image Preloading Content-Policy Check Security Bypass
CVE-2010-0168—remotelinux18 mar 2010
The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in
28RIESGO
abrir ↗
← anteriorpágina 1311 / 2734siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.