Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.417exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.417 exploits
Exploit-DB
Symantec Messaging Gateway 9.5.3-3 - Cross-Site Request Forgery
CVE-2012-0308—webappsmultiple03 dic 2012
Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers
23RIESGO
abrir ↗
Metasploit600
Foswiki MAKETEXT Remote Command Execution
CVE-2012-6329—03 dic 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗
Exploit-DB
IBM System Director Agent - Remote System Level
CVE-2009-0880—remotewindows02 dic 2012
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL 5.1/5.5 (Windows) - 'MySQLJackpot' Remote Command Execution
CVE-2012-5615—remotewindows02 dic 2012
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other ver
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL - Remote User Enumeration
CVE-2012-5615—remotemultiple02 dic 2012
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other ver
28RIESGO
abrir ↗
Exploit-DB
MySQL - Denial of Service (PoC)
CVE-2012-5614—doslinux02 dic 2012
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL (Linux) - Database Privilege Escalation
CVE-2012-5613—locallinux02 dic 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
freeSSHd 2.1.3 - Remote Authentication Bypass
CVE-2012-6066—remotewindows02 dic 2012
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
freeFTPd 1.2.6 - Remote Authentication Bypass
CVE-2012-6066—remotewindows02 dic 2012
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
(SSH.com Communications) SSH Tectia (SSH < 2.0-6.1.9.95 / Tectia 6.1.9.95) - Remote Authentication Bypass
CVE-2012-5975—remotelinux02 dic 2012
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗
Exploit-DB
MySQL (Linux) - Heap Overrun (PoC)
CVE-2012-5612—doslinux02 dic 2012
Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly ot
28RIESGO
abrir ↗
Exploit-DB
MySQL (Linux) - Stack Buffer Overrun (PoC)
CVE-2012-5611—doslinux02 dic 2012
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53
28RIESGO
abrir ↗
Metasploit600
Oracle MySQL for Microsoft Windows FILE Privilege Abuse
CVE-2012-5613—01 dic 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗
Metasploit600
Oracle MySQL for Microsoft Windows MOF Execution
CVE-2012-5613—01 dic 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗
Metasploit300
Android Stock Browser Iframe DOS
CVE-2012-6301—01 dic 2012
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a
18RIESGO
abrir ↗
Metasploit600
Tectia SSH USERAUTH Change Request Password Reset Vulnerability
CVE-2012-5975—01 dic 2012
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗
Metasploit600
Nagios XI Network Monitor Graph Explorer Component Command Injection
CVE-2012-10029HIGH30 nov 2012
Nagios XI Network Monitor Graph Explorer Component < 1.3 Authenticated Command Injection
36RIESGO
abrir ↗
Metasploit300
Symantec Messaging Gateway 9.5 Log File Download Vulnerability
CVE-2012-4347—30 nov 2012
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow r
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Elastix - 'page' Cross-Site Scripting
CVE-2012-6608—webappsphp29 nov 2012
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
CVE-2012-6312—webappsphp29 nov 2012
Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - MIME Type Buffer Overflow (Metasploit)
CVE-2012-3753—remotewindows28 nov 2012
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RIESGO
abrir ↗
Metasploit600
MS13-005 HWND_BROADCAST Low to Medium Integrity Privilege Escalation
CVE-2013-0008—27 nov 2012
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mcrypt 2.5.8 - Local Stack Overflow
CVE-2012-4409—locallinux26 nov 2012
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Forescout CounterACT - 'a' Open Redirection
CVE-2012-4982—webappsmultiple26 nov 2012
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mcrypt 2.6.8 - Stack Buffer Overflow (PoC)
CVE-2012-4409—doslinux26 nov 2012
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗
Metasploit600
Maxthon3 about:history XCS Trusted Zone Code Execution
CVE-2012-10032HIGH26 nov 2012
Maxthon3 about:history XCS Trusted Zone Code Execution
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - TeXML Style Element font-table Field Stack Buffer Overflow (Metasploit)
CVE-2012-3752—remotewindows24 nov 2012
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RIESGO
abrir ↗
Exploit-DB
TrouSerS - Denial of Service
CVE-2012-0698—doslinux23 nov 2012
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetIQ Privileged User Manager 2.3.1 - 'ldapagnt_eval()' Perl Remote Code Execution (Metasploit)
CVE-2012-5932—remotewindows22 nov 2012
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RIESGO
abrir ↗
Exploit-DB
lighttpd 1.4.31 - Denial of Service (PoC)
CVE-2012-5533—doslinux22 nov 2012
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o
28RIESGO
abrir ↗
← anteriorpágina 1164 / 2714siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.