Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Borland Interbase - 'Create-Request' Remote Buffer Overflow (Metasploit)
CVE-2007-3566remotewindows15 jun 2010
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote at
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe - JBIG2Decode Memory Corruption (Metasploit) (1)
CVE-2009-0658localwindows15 jun 2010
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RIESGO
abrir
Exploit-DBVexDay Proof
Borland CaliberRM - StarTeam Multicast Service Buffer Overflow (Metasploit)
CVE-2008-0311remotewindows15 jun 2010
Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (ST
50RIESGO
abrir
Exploit-DBVexDay Proof
PuTTy.exe 0.53 - Remote Buffer Overflow (Metasploit)
CVE-2002-1359remotewindows15 jun 2010
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers
60RIESGO
abrir
Exploit-DBVexDay Proof
MailEnable - IMAPD W3C Logging Buffer Overflow (Metasploit)
CVE-2005-3155remotewindows15 jun 2010
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RIESGO
abrir
Exploit-DBVexDay Proof
Kerio Personal Firewall 2.1.4 - Authentication Packet Overflow (Metasploit)
CVE-2003-0220remotewindows15 jun 2010
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows r
50RIESGO
abrir
Exploit-DBVexDay Proof
Mercury/32 < 4.01b - PH Server Module Buffer Overflow (Metasploit)
CVE-2005-4411remotewindows15 jun 2010
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long requ
50RIESGO
abrir
Exploit-DBVexDay Proof
Smart ASP Survey - Cross-Site Scripting / SQL Injection
CVE-2010-5045webappsasp15 jun 2010
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
SIPfoundry sipXphone 2.6.0.27 - CSeq Buffer Overflow (Metasploit)
CVE-2006-3524remotewindows15 jun 2010
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir
Exploit-DBVexDay Proof
File Sharing Wizard 1.5.0 - Buffer Overflow (PoC)
CVE-2010-2330doswindows15 jun 2010
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (c
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - IDQ Path Overflow (MS01-033) (Metasploit)
CVE-2001-0500remotewindows15 jun 2010
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir
Exploit-DBVexDay Proof
EnjoySAP SAP GUI - ActiveX Control Buffer Overflow (Metasploit)
CVE-2007-3605remotewindows15 jun 2010
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP
50RIESGO
abrir
Exploit-DBVexDay Proof
Yahoo! Messenger 8.1.0.249 - ActiveX Control Buffer Overflow (Metasploit)
CVE-2007-3147remotewindows15 jun 2010
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
50RIESGO
abrir
Exploit-DBVexDay Proof
Quick TFTP Server Pro 2.1 - Transfer-Mode Overflow (Metasploit)
CVE-2008-1610remotewindows15 jun 2010
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RIESGO
abrir
Exploit-DBVexDay Proof
FlipViewer FViewerLoading - ActiveX Control Buffer Overflow (Metasploit)
CVE-2007-2919remotewindows15 jun 2010
Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipView
50RIESGO
abrir
Exploit-DBVexDay Proof
Ipswitch IMail Server - IMAP SEARCH Buffer Overflow (Metasploit)
CVE-2007-3925remotewindows15 jun 2010
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote au
60RIESGO
abrir
Exploit-DBVexDay Proof
Tumbleweed SecureTransport FileTransfer - 'vcst_eu.dll' ActiveX Control Buffer Overflow (Metasploit)
CVE-2008-1724remotewindows15 jun 2010
Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX cont
50RIESGO
abrir
Exploit-DBVexDay Proof
Trellian FTP Client 3.01 - PASV Remote Buffer Overflow (Metasploit)
CVE-2010-1465remotewindows15 jun 2010
Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitr
50RIESGO
abrir
Exploit-DBVexDay Proof
AIM Triton 1.0.4 - CSeq Buffer Overflow (Metasploit)
CVE-2006-3524remotewindows15 jun 2010
Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir
Exploit-DBVexDay Proof
RealPlayer - 'rmoc3260.dll' ActiveX Control Heap Corruption (Metasploit)
CVE-2008-1309remotewindows15 jun 2010
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RIESGO
abrir
Exploit-DBVexDay Proof
ShixxNOTE 6.net - Font Field Overflow (Metasploit)
CVE-2004-1595remotewindows15 jun 2010
Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.
50RIESGO
abrir
Exploit-DBVexDay Proof
XnView 1.97.4 - '.MBM' File Remote Heap Buffer Overflow
CVE-2010-1932remotewindows14 jun 2010
Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a
28RIESGO
abrir
Exploit-DBVexDay Proof
Python 3.2 - 'audioop' Module Memory Corruption
CVE-2010-2089dosunix14 jun 2010
The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string length
28RIESGO
abrir
Exploit-DBVexDay Proof
VideoWhisper PHP 2 Way Video Chat - 'r' Cross-Site Scripting
CVE-2010-4971webappsphp14 jun 2010
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF 3.9.4 - Unknown Tag Second Pass Processing Remote Denial of Service
CVE-2010-2631doslinux14 jun 2010
LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly ha
23RIESGO
abrir
Exploit-DBVexDay Proof
Digital Interchange Document Library - SQL Injection
CVE-2010-5021webappsasp13 jun 2010
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
Yamamah Photo Gallery 1.00 - 'calbums' SQL Injection
CVE-2010-1300webappsphp13 jun 2010
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
UTStats - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2010-5009webappsphp13 jun 2010
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Yamamah Photo Gallery 1.00 - 'download.php' Local File Disclosure
CVE-2010-2334webappsphp13 jun 2010
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20
23RIESGO
abrir
Exploit-DBVexDay Proof
UTStats - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2010-5007webappsphp13 jun 2010
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RIESGO
abrir
anteriorpágina 197 / 636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.