Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Ghostscript - '.PostScript' File Stack Overflow
CVE-2010-1869localbsd18 jul 2010
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
rpc.pcnfsd - Remote Format String
CVE-2010-1039remoteaix18 jul 2010
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Automatic .LNK Shortcut File Code Execution
CVE-2015-0096localwindows18 jul 2010
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir
Exploit-DBVexDay Proof
Kayako eSupport 3.70.02 - SQL Injection
CVE-2010-2911webappsphp17 jul 2010
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component StaticXT - SQL Injection
CVE-2010-2919webappsphp17 jul 2010
SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
MoreAmp - Local Buffer Overflow (SEH) (Metasploit)
CVE-2010-2439localwindows17 jul 2010
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RIESGO
abrir
Exploit-DBVexDay Proof
Kayako eSupport 3.70.02 - SQL Injection
CVE-2010-2912webappsphp17 jul 2010
SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell Groupwise Internet Agent - Stack Overflow
CVE-2010-2777dosmultiple16 jul 2010
Stack-based buffer overflow in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise 7.x befo
28RIESGO
abrir
Exploit-DBVexDay Proof
Mini-stream RM-MP3 Converter 3.1.2.1 - '.pls' Local Stack Buffer Overflow Universal
CVE-2010-5081localwindows_x8616 jul 2010
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code vi
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Daxctle.OCX KeyFrame Method Heap Buffer Overflow (MS06-067) (Metasploit)
CVE-2006-4777remotewindows16 jul 2010
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir
Exploit-DBVexDay Proof
Pre Podcast Portal - Authentication Bypass
CVE-2010-4959webappsphp16 jul 2010
SQL injection vulnerability in the login feature in Pre Projects Pre Podcast Portal allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
BS Scripts Directory - 'articlesdetails.php' SQL Injection
CVE-2010-2906webappsphp16 jul 2010
SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP DB 7.4 - WebTools Buffer Overflow (Metasploit)
CVE-2007-3614remotewindows16 jul 2010
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, all
60RIESGO
abrir
Exploit-DBVexDay Proof
BS Scripts Directory - 'info.php' SQL Injection
CVE-2010-2905webappsphp15 jul 2010
SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Samba 2.2.8 (Linux x86) - 'trans2open' Remote Overflow (Metasploit)
CVE-2003-0201remotelinux_x8614 jul 2010
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir
Exploit-DBVexDay Proof
Nagios3 - 'statuswml.cgi' 'Ping' Command Execution (Metasploit)
CVE-2009-2288webappscgi14 jul 2010
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - 0x5D record Stack Overflow (MS10-038)
CVE-2010-0822localwindows14 jul 2010
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RIESGO
abrir
Exploit-DBVexDay Proof
Samba 3.0.24 (Linux) - 'lsa_io_trans_names' Heap Overflow (Metasploit)
CVE-2007-2446remotelinux14 jul 2010
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir
Exploit-DBVexDay Proof
IPSwitch WhatsUp Gold 8.03 - Remote Buffer Overflow (Metasploit)
CVE-2004-0798remotewindows14 jul 2010
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to
50RIESGO
abrir
Exploit-DBVexDay Proof
Free Download Manager 2.5 Build 758 - Remote Control Server Buffer Overflow (Metasploit)
CVE-2009-0183remotewindows13 jul 2010
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris - 'nfslogd' Insecure Temporary File Creation
CVE-2010-2383localsolaris13 jul 2010
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris Management Console - WBEM Insecure Temporary File Creation
CVE-2010-2384localsolaris13 jul 2010
Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality and integrity via unkn
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle WebLogic Server 10.3.3 - Encoded URL
CVE-2010-2375remotemultiple13 jul 2010
Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server componen
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Business Process Management 10.3.2 - Cross-Site Scripting
CVE-2010-2370remotemultiple13 jul 2010
Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 M
23RIESGO
abrir
Exploit-DBVexDay Proof
eDirectory 8.7.3 - iMonitor Remote Stack Buffer Overflow (Metasploit)
CVE-2005-2551remotewindows13 jul 2010
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of se
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris - 'rdist' Privilege Escalation
CVE-2010-0916dossolaris13 jul 2010
Unspecified vulnerability in Oracle OpenSolaris 10 allows local users to affect confidentiality, integrity, and availabi
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF 3.9.4 - Out-Of-Order Tag Type Mismatch Remote Denial of Service
CVE-2010-2630doslinux12 jul 2010
The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that ha
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris 8/9/10 - 'flar' Insecure Temporary File Creation
CVE-2010-2382localsolaris12 jul 2010
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux PAM 1.1.0 (Ubuntu 9.10/10.04) - MOTD File Tampering Privilege Escalation (2)
CVE-2010-0832locallinux12 jul 2010
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 - CFunctionPointer Uninitialized Memory Corruption (MS09-002) (Metasploit)
CVE-2009-0075remotewindows12 jul 2010
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
anteriorpágina 189 / 636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.