Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.210exploits catalogados
36.420CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Elastix - 'page' Cross-Site Scripting
CVE-2012-6608webappsphp29 nov 2012
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
CVE-2012-6312webappsphp29 nov 2012
Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime 7.7.2 - MIME Type Buffer Overflow (Metasploit)
CVE-2012-3753remotewindows28 nov 2012
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RIESGO
abrir
Exploit-DBVexDay Proof
mcrypt 2.6.8 - Stack Buffer Overflow (PoC)
CVE-2012-4409doslinux26 nov 2012
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir
Exploit-DBVexDay Proof
Forescout CounterACT - 'a' Open Redirection
CVE-2012-4982webappsmultiple26 nov 2012
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to
38RIESGO
abrir
Exploit-DBVexDay Proof
mcrypt 2.5.8 - Local Stack Overflow
CVE-2012-4409locallinux26 nov 2012
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime 7.7.2 - TeXML Style Element font-table Field Stack Buffer Overflow (Metasploit)
CVE-2012-3752remotewindows24 nov 2012
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RIESGO
abrir
Exploit-DBVexDay Proof
NetIQ Privileged User Manager 2.3.1 - 'ldapagnt_eval()' Perl Remote Code Execution (Metasploit)
CVE-2012-5932remotewindows22 nov 2012
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RIESGO
abrir
Exploit-DBVexDay Proof
dotProject 2.1.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-5702webappsphp21 nov 2012
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
dotProject 2.1.x - 'index.php' Multiple SQL Injections
CVE-2012-5701webappsphp21 nov 2012
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute a
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell File Reporter (NFR) Agent FSFUI Record - Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2012-4959remotewindows19 nov 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir
Exploit-DBVexDay Proof
BabyGekko 1.2.2e - Multiple Vulnerabilities
CVE-2012-5698webappsphp15 nov 2012
BabyGekko before 1.2.4 has SQL injection.
23RIESGO
abrir
Exploit-DBVexDay Proof
BabyGekko 1.2.2e - Multiple Vulnerabilities
CVE-2012-5699webappsphp15 nov 2012
BabyGekko before 1.2.4 allows PHP file inclusion.
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Database Client System Analyzer - Arbitrary File Upload (Metasploit)
CVE-2010-3600remotewindows15 nov 2012
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RIESGO
abrir
Exploit-DBVexDay Proof
BabyGekko 1.2.2e - Multiple Vulnerabilities
CVE-2012-5700webappsphp15 nov 2012
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell NetIQ Privileged User Manager 2.3.1 - 'auth.dll' pa_modify_accounts() Remote Code Execution
CVE-2012-5930remotewindows15 nov 2012
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does n
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell NetIQ Privileged User Manager 2.3.1 - 'auth.dll' pa_modify_accounts() Remote Code Execution
CVE-2012-5931remotewindows15 nov 2012
Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User M
23RIESGO
abrir
Exploit-DBVexDay Proof
MYREphp Vacation Rental Software - Multiple Vulnerabilities
CVE-2012-6587webappsphp14 nov 2012
Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows
23RIESGO
abrir
Exploit-DBVexDay Proof
dotProject 2.1.6 - Remote File Inclusion
CVE-2006-0755MEDIUMwebappsphp14 nov 2012
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allo
33RIESGO
abrir
Exploit-DBVexDay Proof
Myrephp Business Directory - Multiple Vulnerabilities
CVE-2012-6589webappsphp14 nov 2012
Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
MYRE Realty Manager - Multiple Vulnerabilities
CVE-2012-6584webappsphp14 nov 2012
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Myrephp Business Directory - Multiple Vulnerabilities
CVE-2012-6588webappsphp14 nov 2012
SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
MYREphp Vacation Rental Software - Multiple Vulnerabilities
CVE-2012-6586webappsphp14 nov 2012
Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
MYRE Realty Manager - Multiple Vulnerabilities
CVE-2012-6585webappsphp14 nov 2012
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
IrfanView - '.TIF' Image Decompression Buffer Overflow
CVE-2009-5022doswindows13 nov 2012
Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execut
28RIESGO
abrir
Exploit-DBVexDay Proof
Java Applet - JAX-WS Remote Code Execution (Metasploit)
CVE-2012-5067remotemultiple13 nov 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
35RIESGO
abrir
Exploit-DBVexDay Proof
Java Applet - JAX-WS Remote Code Execution (Metasploit)
CVE-2012-5076CRITICALbajo ataqueremotemultiple13 nov 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RIESGO
abrir
Exploit-DBVexDay Proof
Huawei (Multiple Products) - Password Encryption
CVE-2012-4960remotehardware13 nov 2012
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605
23RIESGO
abrir
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 3.3.4 - 'Unserialize()' PHP Code Execution (Metasploit)
CVE-2012-5692remotephp13 nov 2012
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RIESGO
abrir
Exploit-DBVexDay Proof
ESRI ArcGIS for Server - 'where' SQL Injection
CVE-2012-4949webappsmultiple09 nov 2012
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via
23RIESGO
abrir
anteriorpágina 115 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.