Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Joomla! Component allCineVid 1.0.0 - Blind SQL Injection
CVE-2011-0511webappsphp18 ene 2011
SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
phpCMS 2008 V2 - 'data.php' SQL Injection
CVE-2011-0645webappsphp17 ene 2011
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Fusion Teams Structure Infusion Addon - SQL Injection
CVE-2011-0512webappsphp17 ene 2011
SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
AWBS 2.9.2 - 'cart.php' Blind SQL Injection
CVE-2011-0510webappsphp16 ene 2011
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
CakePHP 1.3.5/1.2.8 - Cache Corruption (Metasploit)
CVE-2010-4335webappsphp14 ene 2011
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RIESGO
abrir
Exploit-DBVexDay Proof
Objectivity/DB - Lack of Authentication
CVE-2011-0489doswindows14 ene 2011
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft WMI Administration Tools - ActiveX Buffer Overflow (Metasploit)
CVE-2010-3973remotewindows14 ene 2011
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in
60RIESGO
abrir
Exploit-DBVexDay Proof
Blackmoon FTP 3.1 Build 1735/1736 - Denial of Service
CVE-2011-0507doswindows13 ene 2011
FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.173
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Win32k - Keyboard Layout (MS10-073)
CVE-2010-2743localwindows13 ene 2011
The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during
43RIESGO
abrir
Exploit-DBVexDay Proof
SiteScape Enterprise Forum 7 - TCL Injection
CVE-2007-6515webappscgi13 ene 2011
support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator charact
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Data Access Components - Remote Overflow (MS11-002)
CVE-2011-0027remotewindows12 ene 2011
Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properl
35RIESGO
abrir
Exploit-DBVexDay Proof
Mono/Moonlight Generic Type Argument - Privilege Escalation
CVE-2010-4254doslinux11 ene 2011
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft RPC DCOM Interface - Remote Overflow (MS03-026) (Metasploit)
CVE-2003-0352remotewindows11 ene 2011
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RIESGO
abrir
Exploit-DBVexDay Proof
Nokia MultiMedia Player 1.0 - Local Overflow (SEH Unicode)
CVE-2011-0498localwindows11 ene 2011
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted r
23RIESGO
abrir
Exploit-DBVexDay Proof
Lotus CMS Fraise 3.0 - Local File Inclusion / Remote Code Execution
CVE-2011-0518webappsphp10 ene 2011
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir
Exploit-DBVexDay Proof
JBoss JMX - Console Beanshell Deployer WAR Upload and Deployment (Metasploit)
CVE-2010-0738MEDIUMbajo ataqueransomwareremotemultiple10 ene 2011
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Common Control Library 'Comctl32' Heap Overflow (MS10-081)
CVE-2010-2746remotewindows10 ene 2011
Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
TinyBB 1.2 - SQL Injection
CVE-2011-0443webappsphp10 ene 2011
SQL injection vulnerability in inc/tinybb-settings.php in tinyBB 1.2, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.2 rc3 < 1.3.3b (Linux) - Telnet IAC Buffer Overflow (Metasploit)
CVE-2010-4221remotelinux09 ene 2011
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.2 < 1.3.0 (Linux) - 'sreplace' Remote Buffer Overflow (Metasploit)
CVE-2006-5815remotelinux09 ene 2011
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably auth
60RIESGO
abrir
Exploit-DBVexDay Proof
KingView 6.5.3 - SCADA HMI Heap Overflow
CVE-2011-0406remotewindows09 ene 2011
Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary co
28RIESGO
abrir
Exploit-DBVexDay Proof
Sun Java - Runtime New Plugin docbase Buffer Overflow (Metasploit)
CVE-2010-3552remotewindows08 ene 2011
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RIESGO
abrir
Exploit-DBVexDay Proof
NetSupport Manager Agent - Remote Buffer Overflow (1)
CVE-2011-0404remotemultiple08 ene 2011
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RIESGO
abrir
Exploit-DBVexDay Proof
Signed Applet Social Engineering - Code Execution (Metasploit)
CVE-2008-5353remotemultiple08 ene 2011
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - mDNSResponder UPnP Location Overflow (Metasploit)
CVE-2007-2386remoteosx08 ene 2011
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of servic
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime 7.6.7 - _Marshaled_pUnk Code Execution (Metasploit)
CVE-2010-1818localwindows08 ene 2011
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox CE 2.6.1 - 'langChoice' Local File Inclusion (Metasploit)
CVE-2008-6825webappsphp08 ene 2011
Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to
43RIESGO
abrir
Exploit-DBVexDay Proof
VeryTools VideoSpirit Pro 1.68 - Local Buffer Overflow
CVE-2011-0500localwindows08 ene 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft IIS/PWS - CGI Filename Double Decode Command Execution (MS01-026) (Metasploit)
CVE-2001-0333remotewindows08 ene 2011
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector Manager 6.11 - RDS Service Remote Denial of Service
CVE-2011-0514doswindows08 ene 2011
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash)
50RIESGO
abrir
anteriorpágina 163 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.