Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
CA BrightStor Discovery Service - TCP Overflow (Metasploit)
CVE-2005-2535remotewindows30 abr 2010
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execu
60RIESGO
abrir
Exploit-DBVexDay Proof
SecureCRT 4.0 Beta 2 SSH1 - Remote Buffer Overflow (Metasploit)
CVE-2002-1059remotewindows30 abr 2010
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execut
50RIESGO
abrir
Exploit-DBVexDay Proof
iScripts VisualCaster - SQL Injection
CVE-2010-2853webappsphp29 abr 2010
SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Scratcher - SQL Injection / Cross-Site Scripting
CVE-2010-1742webappsphp29 abr 2010
Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
chCounter - indirect SQL Injection / Cross-Site Scripting
CVE-2009-1347webappsphp29 abr 2010
Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SharePoint Server 2007 - Cross-Site Scripting
CVE-2010-0817webappswindows29 abr 2010
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possi
28RIESGO
abrir
Exploit-DBVexDay Proof
chCounter - indirect SQL Injection / Cross-Site Scripting
CVE-2009-1362webappsphp29 abr 2010
SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
TaskFreak 0.6.2 - SQL Injection
CVE-2010-1583webappsphp29 abr 2010
SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN)
23RIESGO
abrir
Exploit-DBVexDay Proof
Scratcher - SQL Injection / Cross-Site Scripting
CVE-2010-1743webappsphp29 abr 2010
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Exploit-DBVexDay Proof
Samba 2.2.2 < 2.2.6 - 'nttrans' Remote Buffer Overflow (Metasploit) (1)
CVE-2003-0085remotelinux28 abr 2010
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-
45RIESGO
abrir
Exploit-DBVexDay Proof
gpEasy 1.6.1 - Cross-Site Request Forgery (Add Admin)
CVE-2010-2039webappsphp28 abr 2010
Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijac
23RIESGO
abrir
Exploit-DBVexDay Proof
Modelbook - 'casting_view.php' SQL Injection
CVE-2010-1705webappsphp28 abr 2010
SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Services - ConnectFunnel Stack Buffer Overflow (MS10-025) (Metasploit)
CVE-2010-0478remotewindows28 abr 2010
Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 200
50RIESGO
abrir
Exploit-DBVexDay Proof
SoftBizScripts Hosting Script - SQL Injection
CVE-2005-3817webappsphp28 abr 2010
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
SoftBizScripts Dating Script - SQL Injection
CVE-2006-3271webappsphp28 abr 2010
Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Video Battle - SQL Injection
CVE-2010-1701webappsphp28 abr 2010
SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
2DayBiz Auction Script - Authentication Bypass
CVE-2010-1706webappsphp27 abr 2010
Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
memcached 1.4.2 - Memory Consumption Remote Denial of Service
CVE-2010-1152doslinux27 abr 2010
memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a
28RIESGO
abrir
Exploit-DBVexDay Proof
Webkit (Apple Safari 4.0.5) - Blink Tag Stack Exhaustion Denial of Service
CVE-2010-0050doswindows27 abr 2010
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or
28RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component ABC 1.1.7 - SQL Injection
CVE-2010-1656webappsphp27 abr 2010
SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Infocus Real Estate Enterprise Edition Script - Authentication Bypass
CVE-2010-1654webappsphp27 abr 2010
Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Avast! 4.7 - 'aavmker4.sys' Local Privilege Escalation
CVE-2009-3523localwindows27 abr 2010
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1)
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Ultimate Portfolio 1.0 - Local File Inclusion
CVE-2010-1659webappsphp27 abr 2010
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows rem
43RIESGO
abrir
Exploit-DBVexDay Proof
Avast! 4.7 - 'aavmker4.sys' Local Privilege Escalation
CVE-2010-0705localwindows27 abr 2010
Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.34 - 'find_keyring_by_name()' Local Memory Corruption
CVE-2010-1437doslinux27 abr 2010
Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlie
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component SmartSite 1.0.0 - Local File Inclusion
CVE-2010-1657webappsphp27 abr 2010
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RIESGO
abrir
Exploit-DBVexDay Proof
Help Center Live 2.0.6 - 'module=helpcenter&file=' Local File Inclusion
CVE-2010-1652webappsphp27 abr 2010
Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component NoticeBoard 1.3 - Local File Inclusion
CVE-2010-1658webappsphp27 abr 2010
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RIESGO
abrir
Exploit-DBVexDay Proof
CLScript.com Classifieds Software - SQL Injection
CVE-2010-1660webappsphp27 abr 2010
SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeRealty(Free Real Estate Listing Software) - Authentication Bypass
CVE-2010-1708webappsphp27 abr 2010
Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
anteriorpágina 208 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.