Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
CVE-2010-4344CRITICALbajo ataqueremotelinux16 dic 2010
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe PDF - Embedded EXE Social Engineering (Metasploit)
CVE-2010-1240localwindows16 dic 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
CVE-2010-4111webappsphp15 dic 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RIESGO
abrir
Exploit-DB
Pointter PHP Micro-Blogging Social Network - Unauthorized Privilege Escalation
CVE-2010-4333webappsphp15 dic 2010
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
CVE-2010-4348webappsphp15 dic 2010
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attacker
23RIESGO
abrir
Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
CVE-2010-4750webappsphp15 dic 2010
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allow
23RIESGO
abrir
Exploit-DB
Pointter PHP Content Management System - Unauthorized Privilege Escalation
CVE-2010-4332webappsphp15 dic 2010
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Local File Inclusion
CVE-2010-4350webappsphp15 dic 2010
Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to in
23RIESGO
abrir
Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
CVE-2010-4749webappsphp15 dic 2010
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
CVE-2010-4349webappsphp15 dic 2010
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an inv
23RIESGO
abrir
Exploit-DBVexDay Proof
Java - 'Statement.invoke()' Trusted Method Chain (Metasploit)
CVE-2010-0840CRITICALbajo ataqueremotemultiple15 dic 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RIESGO
abrir
Exploit-DB
BEdita 3.0.1.2550 - Multiple Vulnerabilities
CVE-2010-5315webappsphp15 dic 2010
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the aut
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - CSS Parser
CVE-2010-3971remotewindows15 dic 2010
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir
Exploit-DBVexDay Proof
gitWeb 1.7.3.3 - Cross-Site Scripting
CVE-2010-3906webappscgi15 dic 2010
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
CVE-2010-4604locallinux15 dic 2010
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-3843remotemultiple14 dic 2010
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - DHTML Behaviour Use-After-Free (MS10-018) (Metasploit)
CVE-2010-0806HIGHbajo ataqueremotewindows14 dic 2010
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2010-4094remotemultiple14 dic 2010
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-4189remotemultiple14 dic 2010
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RIESGO
abrir
Exploit-DB
FontForge - '.BDF' Font File Stack Buffer Overflow (PoC)
CVE-2010-4259doslinux14 dic 2010
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application cras
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple14 dic 2010
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2009-4188remotemultiple14 dic 2010
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RIESGO
abrir
Exploit-DBVexDay Proof
Axis2 / SAP BusinessObjects - (Authenticated) Code Execution (via SOAP) (Metasploit)
CVE-2010-0219remotemultiple14 dic 2010
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
CVE-2010-0557remotemultiple14 dic 2010
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RIESGO
abrir
Exploit-DBVexDay Proof
Crystal Reports Viewer 12.0.0.549 - 'PrintControl.dll' ActiveX
CVE-2010-2590remotewindows14 dic 2010
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RIESGO
abrir
Exploit-DBVexDay Proof
Axis2 - (Authenticated) Code Execution (via REST) (Metasploit)
CVE-2010-0219remotemultiple14 dic 2010
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
Exploit-DBVexDay Proof
Clear iSpot/Clearspot 2.0.0.0 - Cross-Site Request Forgery
CVE-2010-4507webappshardware12 dic 2010
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 a
23RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.63 - Remote Command Execution
CVE-2010-4344CRITICALbajo ataqueremotelinux11 dic 2010
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RIESGO
abrir
Exploit-DB
PHP 5.3.3 - NumberFormatter::getSymbol Integer Overflow
CVE-2010-4409dosmultiple10 dic 2010
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows cont
28RIESGO
abrir
Exploit-DB
VMware Tools - Update OS Command Injection
CVE-2010-4297remotemultiple09 dic 2010
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 3
23RIESGO
abrir
anteriorpágina 334 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.