Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.526exploits catalogados
36.593CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
eZip Wizard 3.0 - '.zip' File (SEH)
CVE-2009-1028localwindows04 abr 2010
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RIESGO
abrir
Exploit-DBVexDay Proof
nodesforum 1.033 - Remote File Inclusion
CVE-2010-1351webappsphp04 abr 2010
Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allo
23RIESGO
abrir
Exploit-DBVexDay Proof
ZipCentral - '.zip' File (SEH)
CVE-2006-2439localwindows04 abr 2010
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP
23RIESGO
abrir
Exploit-DBVexDay Proof
Facil-CMS 0.1RC2 - Local/Remote File Inclusion
CVE-2008-7176webappsphp04 abr 2010
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component JP Jobs 1.4.1 - SQL Injection
CVE-2010-1350webappsphp03 abr 2010
SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
IncrediMail 2.0 - ActiveX (Authenticated) Buffer Overflow (PoC)
CVE-2010-5289doswindows03 abr 2010
Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2
23RIESGO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Overflow
CVE-2011-5165localwindows02 abr 2010
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Exploit-DBVexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Buffer Overflow
CVE-2008-4779localwindows01 abr 2010
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Reader - Escape From '.PDF' Execute Embedded Executable
CVE-2010-1239localwindows31 mar 2010
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Act
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Reader - Escape From '.PDF' Execute Embedded Executable
CVE-2010-1240localwindows31 mar 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir
Exploit-DBVexDay Proof
Piwik 0.5.5 - 'form_url' Cross-Site Scripting
CVE-2010-1453webappsphp31 mar 2010
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to injec
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component DW Graph - Local File Inclusion
CVE-2010-1302webappsphp31 mar 2010
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! a
38RIESGO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Stack Buffer Overflow
CVE-2011-5165localwindows31 mar 2010
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Exploit-DBVexDay Proof
Centreon IT & Network Monitoring 2.1.5 - SQL Injection
CVE-2010-1301webappsphp31 mar 2010
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
CVE-2010-1309webappsphp30 mar 2010
Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Shadow Stream Recorder 3.0.1.7 - '.asx' Local Buffer Overflow
CVE-2009-1642localwindows30 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow
CVE-2009-1642localwindows30 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
CVE-2008-7254webappsphp30 mar 2010
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, w
23RIESGO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' (PoC)
CVE-2011-5165doswindows30 mar 2010
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Exploit-DBVexDay Proof
Easy-Clanpage 2.1 - SQL Injection
CVE-2008-1425webappsmultiple30 mar 2010
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
CVE-2009-1642doswindows29 mar 2010
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_weblinks - 'id' SQL Injection
CVE-2010-2679webappsphp29 mar 2010
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Devana - SQL Injection
CVE-2010-2673webappsphp28 mar 2010
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-2675webappsphp28 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
CVE-2010-1270webappsphp28 mar 2010
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
CVE-2010-1269webappsphp28 mar 2010
SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
CVE-2010-2674webappsphp28 mar 2010
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Uebimiau Webmail 2.7.2 - Multiple Vulnerabilities
CVE-2007-5235webappsphp27 mar 2010
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
CVE-2010-2677webappsphp27 mar 2010
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is dis
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
CVE-2010-2676webappsphp27 mar 2010
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers
23RIESGO
abrir
anteriorpágina 214 / 636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.