Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Microsoft ASP.NET - Padding Oracle File Download (MS10-070)
CVE-2010-3332remoteasp17 oct 2010
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RIESGO
abrir
Exploit-DBVexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
CVE-2010-4144webappsasp17 oct 2010
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NTLM Weak Nonce (MS10-012)
CVE-2010-0231remotewindows17 oct 2010
The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003
35RIESGO
abrir
Exploit-DBVexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
CVE-2010-4145webappsasp17 oct 2010
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - 'HtmlDlgHelper' Class Memory Corruption (MS10-071)
CVE-2010-3329doswindows16 oct 2010
mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Micr
28RIESGO
abrir
Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
CVE-2010-4055dosmultiple15 oct 2010
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denia
23RIESGO
abrir
Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
CVE-2010-4057dosmultiple15 oct 2010
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RIESGO
abrir
Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
CVE-2010-4056dosmultiple15 oct 2010
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RIESGO
abrir
Exploit-DBVexDay Proof
DATAC RealWin SCADA Server 2.0 (Build 6.1.8.10) - Buffer Overflow
CVE-2010-4142doswindows15 oct 2010
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RIESGO
abrir
Exploit-DBVexDay Proof
TWiki 5.0 - bin/login Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-3841webappsphp14 oct 2010
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
TWiki 5.0 - '/bin/view?rev' Cross-Site Scripting
CVE-2010-3841webappsphp14 oct 2010
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Jstore - 'Controller' Local File Inclusion
CVE-2010-5286webappsphp13 oct 2010
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary
43RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
CVE-2010-3552remotewindows13 oct 2010
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 3.5.10/3.6.6 - 'WMP' Memory Corruption Using Popups
CVE-2010-2745doswindows13 oct 2010
Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, w
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris - 'su' Crash
CVE-2010-3503dossolaris13 oct 2010
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrit
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp 5.5.8.2985 - Multiple Buffer Overflows
CVE-2010-4371doswindows13 oct 2010
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vect
23RIESGO
abrir
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.53/7.51 - 'OVAS.exe' Stack Buffer Overflow (Metasploit)
CVE-2008-1697remotewindows12 oct 2010
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RIESGO
abrir
Exploit-DBVexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
CVE-2010-5285webappsphp12 oct 2010
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the a
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Fusion Middleware 10.1.2/10.1.3 - BPEL Console Cross-Site Scripting
CVE-2010-3581webappsjsp12 oct 2010
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
AdaptCMS 2.0.1 Beta - Remote File Inclusion (Metasploit)
CVE-2010-2618webappsphp12 oct 2010
PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is ena
23RIESGO
abrir
Exploit-DBVexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
CVE-2010-5284webappsphp12 oct 2010
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
BaconMap 1.0 - SQL Injection
CVE-2010-4800webappsphp11 oct 2010
SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Exploit-DBVexDay Proof
OrangeHRM 2.6.0.1 - Local File Inclusion
CVE-2010-4798webappsphp11 oct 2010
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
BaconMap 1.0 - Local File Disclosure
CVE-2010-4801webappsphp11 oct 2010
Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Fusion Mod Mg User Fotoalbum 1.0.1 - SQL Injection
CVE-2010-4791webappsphp10 oct 2010
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user
23RIESGO
abrir
Exploit-DBVexDay Proof
Site2Nite Auto e-Manager - SQL Injection
CVE-2010-4793webappsasp10 oct 2010
SQL injection vulnerability in detail.asp in Site2Nite Auto e-Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX EvoCam Web Server - GET Buffer Overflow (Metasploit)
CVE-2010-2309remoteosx09 oct 2010
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime (Mac OSX) - RTSP Content-Type Overflow (Metasploit)
CVE-2007-6166remoteosx09 oct 2010
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RIESGO
abrir
Exploit-DBVexDay Proof
hplip - 'hpssd.py' From Address Arbitrary Command Execution (Metasploit)
CVE-2007-5208remotelinux09 oct 2010
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent a
50RIESGO
abrir
Exploit-DBVexDay Proof
ClamAV Milter - Blackhole-Mode Remote Code Execution (Metasploit)
CVE-2007-4560remotelinux09 oct 2010
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary command
60RIESGO
abrir
anteriorpágina 344 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.