Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
82.004 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component CCNewsLetter - Directory Traversal
CVE-2010-0467—webappsphp28 ene 2010
Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attac
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novaboard 1.1.2 - SQL Injection
CVE-2010-0608—webappsphp28 ene 2010
SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Geo++ GNCASTER 1.4.0.7 - GET Denial of Service
CVE-2010-0552—doslinux27 ene 2010
Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
iOS Serversman 3.1.5 - HTTP Remote Denial of Service
CVE-2010-0496—dosios27 ene 2010
FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a deni
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PostgreSQL - 'bitsubstr' Buffer Overflow
CVE-2010-0442—doslinux27 ene 2010
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Geo++ GNCASTER 1.4.0.7 NMEA-data - Denial of Service
CVE-2010-0553—doslinux27 ene 2010
Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) an
23RIESGO
abrir ↗
Metasploit500
Wireshark LWRES Dissector getaddrsbyname_request Buffer Overflow (loop)
CVE-2010-0304—27 ene 2010
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RIESGO
abrir ↗
Metasploit500
Wireshark LWRES Dissector getaddrsbyname_request Buffer Overflow
CVE-2010-0304—27 ene 2010
Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM DB2 - 'REPEAT()' Local Heap Buffer Overflow
CVE-2010-0462—localunix27 ene 2010
Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated use
23RIESGO
abrir ↗
Exploit-DB
South River Technologies WebDrive Service 9.02 build 2232 - Bad Security Descriptor Privilege Escalation
CVE-2009-4606—localwindows26 ene 2010
South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which all
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Secure Desktop 3.x - 'translation' Cross-Site Scripting
CVE-2010-0440—remotehardware26 ene 2010
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions bef
23RIESGO
abrir ↗
Metasploit400
MySQL yaSSL CertDecoder::GetName Buffer Overflow
CVE-2009-4484—25 ene 2010
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.
50RIESGO
abrir ↗
Exploit-DB
Joomla! Component com_mochigames - SQL Injection
CVE-2010-0459—webappswindows24 ene 2010
SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! al
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
magic-portal 2.1 - SQL Injection
CVE-2010-0457—webappsphp23 ene 2010
SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB
Joomla! Component com_casino - SQL Injection
CVE-2010-0461—webappsphp23 ene 2010
SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_gameserver - SQL Injection
CVE-2010-0456—webappsphp22 ene 2010
SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Chrome 3.0 - Style Sheet redirection Information Disclosure
CVE-2010-0315—remotemultiple22 ene 2010
WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's targe
23RIESGO
abrir ↗
Metasploit500
S.O.M.P.L 1.0 Player Buffer Overflow
CVE-2012-10053CRITICAL22 ene 2010
Simple Web Server Connection Header Buffer Overflow
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java System Web Server 6.1/7.0 - WebDAV Format String
CVE-2010-0388—dosmultiple22 ene 2010
Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Blog System 1.x - 'note' SQL Injection
CVE-2010-0458—webappsphp21 ene 2010
Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java System Web Server 6.1/7.0 - Digest Authentication Remote Buffer Overflow
CVE-2010-0387—remotemultiple21 ene 2010
Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - URI Validation Remote Code Execution
CVE-2010-0027—remotewindows21 ene 2010
The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API functi
35RIESGO
abrir ↗
Metasploit300
MS10-002 Microsoft Internet Explorer Object Memory Use-After-Free
CVE-2010-0248HIGH21 ene 2010
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers
68RIESGO
abrir ↗
Metasploit200
AOL 9.5 Phobos.Playlist Import() Stack-based Buffer Overflow
CVE-2010-10015HIGH20 ene 2010
AOL <= 9.5 Phobos.Playlist 'Import()' Stack-Based Buffer Overflow
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
kloNews 2.0 - 'cat.php' Cross-Site Scripting
CVE-2010-1112—webappsphp20 ene 2010
Cross-site scripting (XSS) vulnerability in cat.php in KloNews 2.0 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Metasploit500
Sun Java System Web Server WebDAV OPTIONS Buffer Overflow
CVE-2010-0361—20 ene 2010
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update
60RIESGO
abrir ↗
Metasploit500
Windows SYSTEM Escalation via KiTrap0D
CVE-2010-0232HIGHbajo ataque19 ene 2010
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DataLife Engine 8.3 - '/engine/inc/help.php?config[langs]' Remote File Inclusion
CVE-2010-2005—webappsphp19 ene 2010
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7 - 'KiTrap0D' User Mode to Ring Escalation (MS10-015)
CVE-2010-0232HIGHbajo ataquelocalwindows19 ene 2010
The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Se
91RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DataLife Engine 8.3 - '/engine/ajax/pm.php?config[lang]' Remote File Inclusion
CVE-2010-2005—webappsphp19 ene 2010
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗
← anteriorpágina 1319 / 2734siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.