Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.408exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
81.409 exploits
Exploit-DB✓ VexDay Proof
IBM Lotus Notes Client URL Handler - Command Injection (Metasploit)
CVE-2012-2174—remotewindows25 dic 2012
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted
50RIESGO
abrir ↗
Metasploit200
Nvidia (nvsvc) Display Driver Service Local Privilege Escalation
CVE-2013-0109—25 dic 2012
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TWiki MAKETEXT - Remote Command Execution (Metasploit)
CVE-2012-6329—remoteunix23 dic 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foswiki MAKETEXT - Remote Command Execution (Metasploit)
CVE-2012-6330—remoteunix23 dic 2012
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows r
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foswiki MAKETEXT - Remote Command Execution (Metasploit)
CVE-2012-6329—remoteunix23 dic 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
CVE-2012-5242—webappsphp21 dic 2012
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)
CVE-2013-4710—localandroid21 dic 2012
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)
CVE-2012-6636—localandroid21 dic 2012
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Elite Bulletin Board 2.1.21 - Multiple SQL Injections
CVE-2012-5874—webappsphp21 dic 2012
Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Eli
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
CVE-2012-5243—webappsphp21 dic 2012
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information v
23RIESGO
abrir ↗
Exploit-DB
FireFly Mediaserver 1.0.0.1359 - Null Pointer Dereference
CVE-2012-5875—doswindows21 dic 2012
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1
28RIESGO
abrir ↗
Metasploit600
Android Browser and WebView addJavascriptInterface Code Execution
CVE-2013-4710—21 dic 2012
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir ↗
Metasploit600
Android Browser and WebView addJavascriptInterface Code Execution
CVE-2012-6636—21 dic 2012
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
CVE-2012-5244—webappsphp21 dic 2012
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
InduSoft Web Studio - 'ISSymbol.ocx InternationalSeparator()' Heap Overflow (Metasploit)
CVE-2011-0340—remotewindows20 dic 2012
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Crystal Reports CrystalPrintControl - ActiveX ServerResourceVersion Property Overflow (Metasploit)
CVE-2010-2590—remotewindows18 dic 2012
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
CVE-2013-1744—webappsphp17 dic 2012
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
23RIESGO
abrir ↗
Metasploit600
TWiki MAKETEXT Remote Command Execution
CVE-2012-6329—15 dic 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗
Metasploit300
RealPlayer RealMedia File Handling Buffer Overflow
CVE-2012-5691—14 dic 2012
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers
50RIESGO
abrir ↗
Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
CVE-2012-5992—doshardware13 dic 2012
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software
23RIESGO
abrir ↗
Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
CVE-2012-6007—doshardware13 dic 2012
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) dev
23RIESGO
abrir ↗
Exploit-DB
Centreon Enterprise Server 2.3.3 < 2.3.9-4 - Blind SQL Injection
CVE-2012-5967—webappsphp13 dic 2012
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote
23RIESGO
abrir ↗
Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
CVE-2012-5991—doshardware13 dic 2012
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 3.3.5 - Btrfs CRC32C feature Infinite Loop Local Denial of Service
CVE-2012-5375—doslinux13 dic 2012
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial o
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Portable phpMyAdmin - Authentication Bypass
CVE-2012-5469—webappsphp13 dic 2012
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain ph
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4957—remotewindows12 dic 2012
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4958—remotewindows12 dic 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4959—remotewindows12 dic 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir ↗
Exploit-DB
Axway Secure Transport 5.1 SP2 - Directory Traversal
CVE-2012-4991—webappswindows12 dic 2012
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated use
23RIESGO
abrir ↗
Metasploit300
Novell eDirectory 8 Buffer Overflow
CVE-2012-0432—12 dic 2012
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RIESGO
abrir ↗
← anteriorpágina 1162 / 2714siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.