Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
82.004 exploits
Exploit-DB
Audistats 1.3 - SQL Injection
CVE-2010-1051—webappsphp05 feb 2010
Multiple SQL injection vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Exploit-DB
Audistats 1.3 - SQL Injection
CVE-2010-1052—webappsphp05 feb 2010
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AudiStat 1.3 allow remote attackers to inject arbitr
23RIESGO
abrir ↗
Exploit-DB
Audistats 1.3 - SQL Injection
CVE-2010-1050—webappsphp05 feb 2010
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Exploit-DB
ManageEngine OpUtils 5 - 'Login.DO' SQL Injection
CVE-2010-1044—webappswindows04 feb 2010
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MASA2EL Music City 1.0 - SQL Injection
CVE-2010-1047—webappsphp04 feb 2010
SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 3.4.5 - Symlink Directory Traversal (Metasploit)
CVE-2010-0926—remotelinux04 feb 2010
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sterlite SAM300 AX Router - 'Stat_Radio' Cross-Site Scripting
CVE-2010-0607—remotehardware04 feb 2010
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 3.4.5 - Symlink Directory Traversal
CVE-2010-0926—remotelinux04 feb 2010
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Car Rental-Script - Authentication Bypass
CVE-2010-0631—webappsphp03 feb 2010
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
lighttpd 1.4/1.5 - Slow Request Handling Remote Denial of Service
CVE-2010-0295—doslinux02 feb 2010
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows re
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Evernew Free Joke Script - 'viewjokes.php' SQL Injection
CVE-2010-0630—webappsphp01 feb 2010
SQL injection vulnerability in viewjokes.php in Evernew Free Joke Script 1.2 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB
Home Of AlegroCart 1.1 - Cross-Site Request Forgery (Change Administrator Password)
CVE-2010-1611—webappsphp01 feb 2010
Cross-site request forgery (CSRF) vulnerability in AlegroCart 1.1 allows remote attackers to hijack the authentication o
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component AutartiTarot - Directory Traversal
CVE-2010-0801—webappsphp01 feb 2010
Directory traversal vulnerability in the AutartiTarot (com_autartitarot) component 1.0.3 for Joomla! allows remote authe
23RIESGO
abrir ↗
Metasploit300
Oracle DB 10gR2, 11gR1/R2 DBMS_JVM_EXP_PERMS OS Command Execution
CVE-2010-0866—01 feb 2010
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated u
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service
CVE-2010-0307—doslinux_x86-6401 feb 2010
The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensu
23RIESGO
abrir ↗
Metasploit300
Oracle DB 11g R1/R2 DBMS_JVM_EXP_PERMS OS Code Execution
CVE-2010-0866—01 feb 2010
Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated u
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_simplefaq - 'catid' Blind SQL Injection
CVE-2010-0632—webappsphp30 ene 2010
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RIESGO
abrir ↗
Exploit-DB
IPB (nv2) Awards < 1.1.0 - SQL Injection
CVE-2010-0802—webappsphp30 ene 2010
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Event Calendar - SQL Injection
CVE-2010-0795—webappsphp30 ene 2010
SQL injection vulnerability in the JE Event Calendars (com_jeeventcalendar) component 1.0 for Joomla! allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_dms 2.5.1 - SQL Injection
CVE-2010-0800—webappsphp30 ene 2010
SQL injection vulnerability in the Ossolution Team Documents Seller (aka DMS) (com_dms) component 2.5.1 for Joomla! allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpunity.newsmanager - Local File Inclusion
CVE-2010-0799—webappsphp30 ene 2010
Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component JE Quiz - 'eid' Blind SQL Injection
CVE-2010-0796—webappsphp29 ene 2010
SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hybserv2 - ':help' Denial of Service
CVE-2010-0303—doslinux29 ene 2010
mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a d
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
COMTREND CT-507 IT ADSL Router - 'scvrtsrv.cmd' Cross-Site Scripting
CVE-2010-0470—remotehardware29 ene 2010
Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark 1.2.5 - 'LWRES getaddrbyname' Stack Buffer Overflow (PoC)
CVE-2010-0304—dosmultiple29 ene 2010
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CommonSpot Server - '/utilities/longproc.cfm' Cross-Site Scripting
CVE-2010-0468—webappscfm28 ene 2010
Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novaboard 1.1.2 - SQL Injection
CVE-2010-0608—webappsphp28 ene 2010
SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component jVideoDirect - Blind SQL Injection
CVE-2010-0803—webappsphp28 ene 2010
SQL injection vulnerability in the jVideoDirect (com_jvideodirect) component 1.1 RC3b for Joomla! allows remote attacker
23RIESGO
abrir ↗
Exploit-DB
Rising AntiVirus 2008/2009/2010 - Local Privilege Escalation
CVE-2010-1591—localwindows28 ene 2010
Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, incl
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component CCNewsLetter - Local File Inclusion
CVE-2010-0467—webappsphp28 ene 2010
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RIESGO
abrir ↗
← anteriorpágina 1318 / 2734siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.