Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
acpid 1.0.x - Multiple Local Denial of Service Vulnerabilities
CVE-2011-1159doslinux19 ene 2011
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but
23RIESGO
abrir
Exploit-DB
Simploo CMS 1.7.1 - PHP Code Execution
CVE-2011-0635webappsphp19 ene 2011
Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component allCineVid 1.0.0 - Blind SQL Injection
CVE-2011-0511webappsphp18 ene 2011
SQL injection vulnerability in the allCineVid component (com_allcinevid) 1.0.0 for Joomla! allows remote attackers to ex
23RIESGO
abrir
Exploit-DB
N-13 News 3.4 - Cross-Site Request Forgery (Admin Add)
CVE-2011-0642webappsphp18 ene 2011
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Pango Font Parsing - 'pangoft2-render.c' Heap Corruption
CVE-2011-0020remotelinux18 ene 2011
Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pan
28RIESGO
abrir
Exploit-DB
CakePHP 1.3.5/1.2.8 - 'Unserialize()' File Inclusion
CVE-2010-4335webappsphp18 ene 2011
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RIESGO
abrir
Exploit-DB
Linux Kernel 2.6.32 (Ubuntu 10.04) - '/proc' Handling SUID Privilege Escalation
CVE-2011-1020locallinux17 ene 2011
The proc filesystem implementation in the Linux kernel 2.6.37 and earlier does not restrict access to the /proc director
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Fusion Teams Structure Infusion Addon - SQL Injection
CVE-2011-0512webappsphp17 ene 2011
SQL injection vulnerability in team.php in the Teams Structure module 3.0 for PHP-Fusion allows remote attackers to exec
23RIESGO
abrir
Exploit-DB
SmoothWall Express 3.0 - Multiple Vulnerabilities
CVE-2011-5284webappscgi17 ene 2011
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothw
23RIESGO
abrir
Exploit-DB
SmoothWall Express 3.0 - Multiple Vulnerabilities
CVE-2011-5283webappscgi17 ene 2011
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Expre
23RIESGO
abrir
Exploit-DBVexDay Proof
phpCMS 2008 V2 - 'data.php' SQL Injection
CVE-2011-0645webappsphp17 ene 2011
SQL injection vulnerability in data.php in PHPCMS 2008 V2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DB
Kingsoft AntiVirus 2011 SP5.2 'KisKrnl.sys' 2011.1.13.89 - Local Kernel Mode Denial of Service
CVE-2011-0515doswindows16 ene 2011
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (c
23RIESGO
abrir
Exploit-DB
BetMore Site Suite 4 - 'bid' Blind SQL Injection
CVE-2011-0516webappsphp16 ene 2011
SQL injection vulnerability in mainx_a.php in E-PROMPT C BetMore Site Suite 4.0 through 4.2.0 allows remote attackers to
23RIESGO
abrir
Exploit-DB
Seo Panel 2.2.0 - Cookie-Rendered Persistent Cross-Site Scripting
CVE-2010-4331webappsphp16 ene 2011
Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel 2.2.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
AWBS 2.9.2 - 'cart.php' Blind SQL Injection
CVE-2011-0510webappsphp16 ene 2011
SQL injection vulnerability in cart.php in Advanced Webhost Billing System (AWBS) 2.9.2 and possibly earlier allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Objectivity/DB - Lack of Authentication
CVE-2011-0489doswindows14 ene 2011
The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows rem
28RIESGO
abrir
Exploit-DB
Real Networks RealPlayer SP - 'RecordClip' Method Remote Code Execution
CVE-2010-3749remotewindows14 ene 2011
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows
28RIESGO
abrir
Exploit-DBVexDay Proof
CakePHP 1.3.5/1.2.8 - Cache Corruption (Metasploit)
CVE-2010-4335webappsphp14 ene 2011
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft WMI Administration Tools - ActiveX Buffer Overflow (Metasploit)
CVE-2010-3973remotewindows14 ene 2011
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in
60RIESGO
abrir
Exploit-DB
Sielco Sistemi Winlog 2.07.00 - Stack Overflow
CVE-2011-0517doswindows14 ene 2011
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RIESGO
abrir
Exploit-DBVexDay Proof
Blackmoon FTP 3.1 Build 1735/1736 - Denial of Service
CVE-2011-0507doswindows13 ene 2011
FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.173
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Win32k - Keyboard Layout (MS10-073)
CVE-2010-2743localwindows13 ene 2011
The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during
43RIESGO
abrir
Exploit-DBVexDay Proof
SiteScape Enterprise Forum 7 - TCL Injection
CVE-2007-6515webappscgi13 ene 2011
support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator charact
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Data Access Components - Remote Overflow (MS11-002)
CVE-2011-0027remotewindows12 ene 2011
Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properl
35RIESGO
abrir
Exploit-DBVexDay Proof
Mono/Moonlight Generic Type Argument - Privilege Escalation
CVE-2010-4254doslinux11 ene 2011
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft RPC DCOM Interface - Remote Overflow (MS03-026) (Metasploit)
CVE-2003-0352remotewindows11 ene 2011
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RIESGO
abrir
Exploit-DB
vam shop 1.6 - Multiple Vulnerabilities
CVE-2011-0504webappsphp11 ene 2011
Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote at
23RIESGO
abrir
Exploit-DB
Wireshark - ZigBee ZCL Dissector Infinite Loop Denial of Service
CVE-2010-4301dosmultiple11 ene 2011
epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Nokia MultiMedia Player 1.0 - Local Overflow (SEH Unicode)
CVE-2011-0498localwindows11 ene 2011
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted r
23RIESGO
abrir
Exploit-DB
diafan.cms 4.3 - Multiple Vulnerabilities
CVE-2011-5318webappsphp11 ene 2011
Multiple cross-site request forgery (CSRF) vulnerabilities in diafan.CMS before 5.1 allow remote attackers to hijack the
23RIESGO
abrir
anteriorpágina 330 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.