Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Joomla! Component JE Quotation Form 1.0b1 - Local File Inclusion
CVE-2010-2128webappsphp14 may 2010
Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote a
43RIESGO
abrir
Exploit-DB
Press Release Script - 'page.php?id' SQL Injection
CVE-2010-5047webappsphp14 may 2010
SQL injection vulnerability in page.php in V-EVA Press Release Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component FDione Form Wizard 1.0.2 - Local File Inclusion
CVE-2010-2045webappsphp13 may 2010
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Komento 1.0.0 - 'sid' SQL Injection
CVE-2010-2044webappsphp13 may 2010
SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Alert Management System Intel Alert Originator Service - Remote Buffer Overflow (Metasploit)
CVE-2009-1430remotewindows13 may 2010
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management Syst
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Shockwave Player 11.5.6.606 - 'DIR' Multiple Memory Vulnerabilities
CVE-2010-1280doswindows12 may 2010
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DBVexDay Proof
TomatoCMS 2.0.x - SQL Injection
CVE-2010-1994webappsphp12 may 2010
SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Outlook Express and Windows Mail - Integer Overflow
CVE-2010-0816doswindows11 may 2010
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2
28RIESGO
abrir
Exploit-DBVexDay Proof
Saurus CMS 4.7 - 'edit.php' Cross-Site Scripting
CVE-2010-1997webappsphp11 may 2010
Cross-site scripting (XSS) vulnerability in admin/edit.php in Saurus CMS 4.7.0 allows remote authenticated users, with "
23RIESGO
abrir
Exploit-DBVexDay Proof
AgentX++ Master - AgentX::receive_agentx Stack Buffer Overflow (Metasploit)
CVE-2010-1318remotewindows11 may 2010
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Ser
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 4.0.5 - 'parent.close()' Memory Corruption Code Execution
CVE-2010-1939remotewindows11 may 2010
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using
28RIESGO
abrir
Exploit-DBVexDay Proof
tekno.Portal 0.1b - 'makale.php?id' SQL Injection
CVE-2010-1925webappsphp10 may 2010
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DBVexDay Proof
724CMS Enterprise 4.59 - SQL Injection
CVE-2008-1858webappsphp10 may 2010
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
Exploit-DB
29o3 CMS - 'LibDir' Multiple Remote File Inclusions
CVE-2010-1922webappsphp10 may 2010
Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
CVE-2008-5088webappsphp10 may 2010
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execu
23RIESGO
abrir
Exploit-DBVexDay Proof
Advanced Poll 2.0 - 'mysql_host' Cross-Site Scripting
CVE-2010-2003webappsphp10 may 2010
Cross-site scripting (XSS) vulnerability in misc/get_admin.php in Advanced Poll 2.08 allows remote attackers to inject a
23RIESGO
abrir
Exploit-DB
PHPKB Knowledge Base Software 2.0 - Multilanguage Support Multiple SQL Injections
CVE-2008-1909webappsphp10 may 2010
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan - Remote Stack Buffer Overflow (Metasploit)
CVE-2008-1365remotewindows09 may 2010
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patc
50RIESGO
abrir
Exploit-DBVexDay Proof
Sentinel LM - UDP Buffer Overflow (Metasploit)
CVE-2005-0353remotewindows09 may 2010
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to
60RIESGO
abrir
Exploit-DBVexDay Proof
Macrovision Installshield Update Service - Remote Buffer Overflow (Metasploit)
CVE-2007-5660remotewindows09 may 2010
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RIESGO
abrir
Exploit-DBVexDay Proof
Symantec BackupExec Calendar Control - Remote Buffer Overflow (Metasploit)
CVE-2007-6016remotewindows09 may 2010
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the schedul
50RIESGO
abrir
Exploit-DBVexDay Proof
Knox Arkeia Backup Client Type 77 (OSX) - Remote Overflow (Metasploit)
CVE-2005-0491remoteosx09 may 2010
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RIESGO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.01a - IMAP RENAME Buffer Overflow (Metasploit)
CVE-2004-1211remotewindows09 may 2010
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RIESGO
abrir
Exploit-DBVexDay Proof
SoftiaCom wMailServer 1.0 - Remote Buffer Overflow (Metasploit)
CVE-2005-2287remotewindows09 may 2010
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large T
50RIESGO
abrir
Exploit-DBVexDay Proof
Logitech VideoCall - ActiveX Control Buffer Overflow (Metasploit)
CVE-2007-2918remotewindows09 may 2010
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) View
50RIESGO
abrir
Exploit-DBVexDay Proof
IBM Tivoli Storage Manager Express CAD Service - Remote Buffer Overflow (Metasploit) (1)
CVE-2009-3853remotewindows09 may 2010
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (T
50RIESGO
abrir
Exploit-DBVexDay Proof
Knox Arkeia Backup Client Type 77 (Windows x86) - Remote Overflow (Metasploit)
CVE-2005-0491remotewindows_x8609 may 2010
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Outlook Express - NNTP Response Parsing Buffer Overflow (MS05-030) (Metasploit)
CVE-2005-1213remotewindows09 may 2010
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows rem
60RIESGO
abrir
Exploit-DBVexDay Proof
Novell NetMail 3.52d - IMAP Subscribe Buffer Overflow (Metasploit)
CVE-2006-6761remotewindows09 may 2010
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RIESGO
abrir
Exploit-DBVexDay Proof
freeFTPd 1.0.10 - Key Exchange Algorithm String Buffer Overflow (Metasploit)
CVE-2006-2407remotewindows09 may 2010
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other produc
60RIESGO
abrir
anteriorpágina 376 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.