Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.409exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
81.415 exploits
Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
CVE-2012-6007—doshardware13 dic 2012
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) dev
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4957—remotewindows12 dic 2012
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RIESGO
abrir ↗
Metasploit300
Novell eDirectory 8 Buffer Overflow
CVE-2012-0432—12 dic 2012
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4959—remotewindows12 dic 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
CVE-2012-4958—remotewindows12 dic 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RIESGO
abrir ↗
Exploit-DB
Axway Secure Transport 5.1 SP2 - Directory Traversal
CVE-2012-4991—webappswindows12 dic 2012
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated use
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Data Protector - DtbClsLogin Buffer Overflow (Metasploit)
CVE-2010-3007—remotewindows11 dic 2012
Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x befo
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Smartphone Pentest Framework - Multiple Remote Command Execution Vulnerabilities
CVE-2012-5878—webappscgi10 dic 2012
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary comman
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SimpleInvoices invoices Module - Customer Field Cross-Site Scripting
CVE-2012-4932—webappsphp10 dic 2012
Multiple cross-site scripting (XSS) vulnerabilities in SimpleInvoices before stable-2012-1-CIS3000 allow remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Achievo 1.4.5 - Multiple Vulnerabilities (2)
CVE-2012-5865—webappsphp09 dic 2012
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SumatraPDF 2.1.1/MuPDF 1.0 - Integer Overflow
CVE-2012-5340—doswindows09 dic 2012
SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corru
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Android Kernel 2.6 - Local Denial of Service Crash (PoC)
CVE-2013-1773—dosandroid09 dic 2012
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileg
23RIESGO
abrir ↗
Exploit-DB
Clipbucket 2.6 Revision 738 - Multiple SQL Injections
CVE-2012-5849—webappsphp09 dic 2012
Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbi
23RIESGO
abrir ↗
Metasploit500
Nagios3 history.cgi Host Command Execution
CVE-2012-6096—09 dic 2012
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RIESGO
abrir ↗
Exploit-DB
TVMOBiLi 2.1.0.3557 - Denial of Service
CVE-2012-5451—doswindows09 dic 2012
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a d
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM System Director Agent - DLL Injection (Metasploit)
CVE-2009-0880—remotewindows07 dic 2012
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Simple Gmail Login - Stack Trace Information Disclosure
CVE-2012-6313—webappsphp07 dic 2012
simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sen
23RIESGO
abrir ↗
Metasploit600
FreeFloat FTP Server Arbitrary File Upload
CVE-2012-10030CRITICAL07 dic 2012
FreeFloat FTP Server Arbitrary File Upload
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.0.4 - '.swf' Crash (PoC)
CVE-2013-1868—doswindows07 dic 2012
Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of ser
28RIESGO
abrir ↗
Metasploit400
Netwin SurgeFTP Remote Command Execution
CVE-2012-10028HIGH06 dic 2012
Netwin SurgeFTP <= v23c8 Authenticated RCE
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle MySQL / MariaDB - Insecure Salt Generation Security Bypass
CVE-2012-5627—remotelinux06 dic 2012
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt duri
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle MySQL (Windows) - MOF Execution (Metasploit)
CVE-2012-5613—remotewindows06 dic 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ektron 8.02 - XSLT Transform Remote Code Execution (Metasploit)
CVE-2012-5357—remotewindows05 dic 2012
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
(SSH.com Communications) SSH Tectia - USERAUTH Change Request Password Reset (Metasploit)
CVE-2012-5975—remoteunix05 dic 2012
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Advantech Studio 7.0 - SCADA/HMI Directory Traversal
CVE-2013-1627—webappswindows04 dic 2012
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and
23RIESGO
abrir ↗
Metasploit600
OpenSIS 'modname' PHP Code Execution
CVE-2013-1349—04 dic 2012
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP cod
43RIESGO
abrir ↗
Exploit-DB
Symantec Messaging Gateway 9.5.3-3 - Arbitrary File Download
CVE-2012-4347—webappslinux03 dic 2012
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow r
50RIESGO
abrir ↗
Exploit-DB
Symantec Messaging Gateway 9.5.3-3 - Cross-Site Request Forgery
CVE-2012-0308—webappsmultiple03 dic 2012
Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera Web Browser 12.11 - Crash (PoC)
CVE-2012-6470—doswindows03 dic 2012
Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Metasploit600
Foswiki MAKETEXT Remote Command Execution
CVE-2012-6329—03 dic 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗
← anteriorpágina 1163 / 2714siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.