Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
82.004 exploits
Exploit-DB✓ VexDay Proof
Symantec (Multiple Products) - Client Proxy ActiveX 'CLIproxy.dll' Remote Overflow
CVE-2010-0108—remotewindows17 feb 2010
Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Auktionshaus Gelb 3 - 'news.php' SQL Injection
CVE-2010-0721—webappsphp17 feb 2010
SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iTunes 9.0.1 - '.pls' Handling Buffer Overflow
CVE-2009-2817—localmultiple17 feb 2010
Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of serv
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Erotik Auktionshaus - 'news.php' SQL Injection
CVE-2010-0720—webappsphp17 feb 2010
SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB
Limny 2.0 - Cross-Site Request Forgery (Create Admin User)
CVE-2010-0709—webappsphp16 feb 2010
Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authent
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pogodny CMS - SQL Injection
CVE-2010-0671—webappsphp16 feb 2010
SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BGSvetionik BGS CMS - 'search' Cross-Site Scripting
CVE-2010-0675—webappsphp16 feb 2010
Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arb
23RIESGO
abrir ↗
Metasploit400
Adobe Acrobat Bundled LibTIFF Integer Overflow
CVE-2010-0188HIGHbajo ataqueransomware16 feb 2010
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RIESGO
abrir ↗
Metasploit500
EasyFTP Server CWD Command Stack Buffer Overflow
CVE-2010-20121CRITICAL16 feb 2010
EasyFTP Server <= 1.7.0.11 CWD Command Stack Buffer Overflow
63RIESGO
abrir ↗
Exploit-DB
Limny 2.0 - Cross-Site Request Forgery (Change Email and Password)
CVE-2010-0709—webappsphp16 feb 2010
Multiple cross-site request forgery (CSRF) vulnerabilities in Limny 2.0 allow remote attackers to (1) hijack the authent
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache mod_rewrite - LDAP protocol Buffer Overflow (Metasploit)
CVE-2006-3747—remotewindows15 feb 2010
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and o
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alt-N WebAdmin - USER Buffer Overflow (Metasploit)
CVE-2003-0471—remotewindows15 feb 2010
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Copperleaf Photolog 0.16 - SQL Injection
CVE-2010-0673—webappsphp15 feb 2010
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
JTL-Shop 2 - 'druckansicht.php' SQL Injection
CVE-2010-0691—webappsphp14 feb 2010
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Katalog Stron Hurricane 1.3.5 - Remote File Inclusion / SQL Injection
CVE-2010-0677—webappsphp14 feb 2010
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Katalog Stron Hurricane 1.3.5 - Remote File Inclusion / SQL Injection
CVE-2010-0678—webappsphp14 feb 2010
PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlie
23RIESGO
abrir ↗
Exploit-DB
Joomla! Component Jw_allVideos - Arbitrary File Download
CVE-2010-0696—webappsphp14 feb 2010
Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 throug
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
statcountex 3.1 - Multiple Vulnerabilities
CVE-2010-0674—webappsphp13 feb 2010
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sambar Server 6 - Search Results Buffer Overflow (Metasploit)
CVE-2004-2086—remotewindows13 feb 2010
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Core 2.9 - Failure to Restrict URL Access
CVE-2010-0682—webappsphp13 feb 2010
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
statcountex 3.1 - Multiple Vulnerabilities
CVE-2008-0843—webappsphp13 feb 2010
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WSN Guest 1.02 - 'orderlinks' SQL Injection
CVE-2010-0672—webappsphp13 feb 2010
SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZeusCMS 0.2 - Database Backup Dump / Local File Inclusion
CVE-2010-0681—webappsphp13 feb 2010
ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZeusCMS 0.2 - Database Backup Dump / Local File Inclusion
CVE-2010-0680—webappsphp13 feb 2010
Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Basic-CMS - 'nav_id' Cross-Site Scripting
CVE-2010-0695—webappsphp12 feb 2010
Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB
Hyleos ChemView 1.9.5.1 - ActiveX Control Buffer Overflow (Metasploit)
CVE-2010-0679—remotewindows12 feb 2010
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos Ch
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RSA - SecurID Cross-Site Scripting
CVE-2008-1470—webappsmultiple11 feb 2010
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CD Rentals Script - SQL Injection
CVE-2010-0762—webappsphp11 feb 2010
SQL injection vulnerability in index.php in CommodityRentals CD Rental Software allows remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Collaboration Server 5 - Cross-Site Scripting / Source Code Disclosure
CVE-2010-0641—webappsmultiple11 feb 2010
Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5
23RIESGO
abrir ↗
Exploit-DB
Omnidocs - SQL Injection
CVE-2010-0701—webappsjsp11 feb 2010
SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute ar
23RIESGO
abrir ↗
← anteriorpágina 1316 / 2734siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.