Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - XSLT Integer Overflow
CVE-2010-1199remotelinux22 jun 2010
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4,
28RIESGO
abrir
Exploit-DBVexDay Proof
Texas Imperial Software WFTPD 3.23 - SIZE Overflow (Metasploit)
CVE-2006-4318remotewindows22 jun 2010
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RIESGO
abrir
Exploit-DBVexDay Proof
SafeNet SoftRemote - IKE Service Buffer Overflow (Metasploit)
CVE-2009-1943remotewindows22 jun 2010
Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers
60RIESGO
abrir
Exploit-DBVexDay Proof
CA BrightStor ArcServe - Media Service Stack Buffer Overflow (Metasploit)
CVE-2007-2139remotewindows22 jun 2010
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RIESGO
abrir
Exploit-DBVexDay Proof
BolinTech DreamFTP Server 1.02 - Format String (Metasploit)
CVE-2004-2074remotewindows22 jun 2010
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RIESGO
abrir
Exploit-DBVexDay Proof
GAMSoft TelSrv 1.5 - 'Username' Remote Buffer Overflow (Metasploit)
CVE-2000-0665remotewindows22 jun 2010
GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.
50RIESGO
abrir
Exploit-DBVexDay Proof
Solaris TelnetD - 'TTYPROMPT' Remote Buffer Overflow (2) (Metasploit)
CVE-2001-0797remotesolaris22 jun 2010
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir
Exploit-DBVexDay Proof
Sybase EAServer 5.2 - Remote Stack Buffer Overflow (Metasploit)
CVE-2005-2297remotewindows22 jun 2010
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to e
60RIESGO
abrir
Exploit-DBVexDay Proof
WinComLPD 3.0.2 - Remote Buffer Overflow (Metasploit)
CVE-2008-5159remotewindows22 jun 2010
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earl
50RIESGO
abrir
Exploit-DBVexDay Proof
mIRC 6.34 - PRIVMSG Handling Stack Buffer Overflow (Metasploit)
CVE-2008-4449remotewindows22 jun 2010
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail SMTPD - AUTH CRAM-MD5 Buffer Overflow (Metasploit)
CVE-2007-4440remotewindows22 jun 2010
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, all
50RIESGO
abrir
Exploit-DBVexDay Proof
CA BrightStor Universal Agent - Remote Overflow (Metasploit)
CVE-2005-1018remotewindows22 jun 2010
Buffer overflow in the UniversalAgent for Computer Associates (CA) BrightStor ARCserve Backup allows remote authenticate
50RIESGO
abrir
Exploit-DBVexDay Proof
Sun Solaris Telnet - Remote Authentication Bypass (Metasploit)
CVE-2007-0882remotesolaris22 jun 2010
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterpr
60RIESGO
abrir
Exploit-DBVexDay Proof
Asus Dpcproxy - Remote Buffer Overflow (Metasploit)
CVE-2008-1491remotewindows22 jun 2010
Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 an
60RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Picasa2Gallery 1.2.8 - Local File Inclusion
CVE-2010-2507webappsphp22 jun 2010
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! all
38RIESGO
abrir
Exploit-DBVexDay Proof
K-Search - SQL Injection / Cross-Site Scripting
CVE-2010-2457webappsphp22 jun 2010
Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Solaris Sadmind - Command Execution (Metasploit)
CVE-2003-0722remotemultiple22 jun 2010
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attack
60RIESGO
abrir
Exploit-DBVexDay Proof
Video Community portal - SQL Injection / Cross-Site Scripting
CVE-2010-2459webappsphp22 jun 2010
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Boat Classifieds - SQL Injection
CVE-2010-2687webappsasp22 jun 2010
SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Netcat 1.10 - NT Stack Buffer Overflow (Metasploit)
CVE-2004-1317remotewindows22 jun 2010
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attack
50RIESGO
abrir
Exploit-DBVexDay Proof
Subtitle Translation Wizard 3.0.0 - Overflow (SEH) (PoC)
CVE-2010-2440doswindows22 jun 2010
Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell Groupwise Messenger Client - Remote Buffer Overflow (Metasploit)
CVE-2008-2703remotewindows22 jun 2010
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow rem
50RIESGO
abrir
Exploit-DBVexDay Proof
Cornerstone CMS - SQL Injection
CVE-2010-5287webappsphp22 jun 2010
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Job Search Engine Script - SQL Injection
CVE-2010-2609webappsphp22 jun 2010
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail Server < 4.01b - LOGIN Buffer Overflow (Metasploit)
CVE-2007-1373remotewindows22 jun 2010
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RIESGO
abrir
Exploit-DBVexDay Proof
Samba 2.2.8 (OSX/PPC) - 'trans2open' Remote Overflow (Metasploit)
CVE-2003-0201remoteosx_ppc21 jun 2010
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir
Exploit-DBVexDay Proof
G.CMS Generator - SQL Injection
CVE-2010-2438webappsphp21 jun 2010
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang pa
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere ILOG JRules 6.7 - Cross-Site Scripting
CVE-2010-2433webappsjsp21 jun 2010
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Jamroom 4.0.2/4.1.x - 'forum.php' Cross-Site Scripting
CVE-2010-2463webappsphp21 jun 2010
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Samba 2.2.8 (Solaris SPARC) - 'trans2open' Remote Overflow (Metasploit)
CVE-2003-0201remotesolaris_sparc21 jun 2010
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir
anteriorpágina 195 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.