Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB✓ VexDay Proof
Forescout CounterACT - 'a' Open Redirection
CVE-2012-4982—webappsmultiple26 nov 2012
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mcrypt 2.5.8 - Local Stack Overflow
CVE-2012-4409—locallinux26 nov 2012
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - TeXML Style Element font-table Field Stack Buffer Overflow (Metasploit)
CVE-2012-3752—remotewindows24 nov 2012
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RIESGO
abrir ↗
Exploit-DB
TrouSerS - Denial of Service
CVE-2012-0698—doslinux23 nov 2012
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetIQ Privileged User Manager 2.3.1 - 'ldapagnt_eval()' Perl Remote Code Execution (Metasploit)
CVE-2012-5932—remotewindows22 nov 2012
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RIESGO
abrir ↗
Exploit-DB
lighttpd 1.4.31 - Denial of Service (PoC)
CVE-2012-5533—doslinux22 nov 2012
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
dotProject 2.1.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-5702—webappsphp21 nov 2012
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
dotProject 2.1.x - 'index.php' Multiple SQL Injections
CVE-2012-5701—webappsphp21 nov 2012
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute a
23RIESGO
abrir ↗
Exploit-DB
Apple QuickTime 7.7.2 - Targa image Buffer Overflow
CVE-2012-3755—doswindows20 nov 2012
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of s
28RIESGO
abrir ↗
Metasploit300
CUPS 1.6.1 Root File Read
CVE-2012-5519—20 nov 2012
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator
18RIESGO
abrir ↗
Metasploit300
KingView Log File Parsing Buffer Overflow
CVE-2012-4711—20 nov 2012
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent FSFUI Record - Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2012-4959—remotewindows19 nov 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir ↗
Metasploit300
NFR Agent SRS Record Arbitrary Remote File Access
CVE-2012-4957—16 nov 2012
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RIESGO
abrir ↗
Metasploit500
NFR Agent FSFUI Record File Upload RCE
CVE-2012-4959—16 nov 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir ↗
Metasploit300
NFR Agent FSFUI Record Arbitrary Remote File Access
CVE-2012-4958—16 nov 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RIESGO
abrir ↗
Metasploit300
NFR Agent Heap Overflow Vulnerability
CVE-2012-4956—16 nov 2012
Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary co
30RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BabyGekko 1.2.2e - Multiple Vulnerabilities
CVE-2012-5698—webappsphp15 nov 2012
BabyGekko before 1.2.4 has SQL injection.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BabyGekko 1.2.2e - Multiple Vulnerabilities
CVE-2012-5699—webappsphp15 nov 2012
BabyGekko before 1.2.4 allows PHP file inclusion.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell NetIQ Privileged User Manager 2.3.1 - 'auth.dll' pa_modify_accounts() Remote Code Execution
CVE-2012-5930—remotewindows15 nov 2012
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does n
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BabyGekko 1.2.2e - Multiple Vulnerabilities
CVE-2012-5700—webappsphp15 nov 2012
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.2f allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Database Client System Analyzer - Arbitrary File Upload (Metasploit)
CVE-2010-3600—remotewindows15 nov 2012
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell NetIQ Privileged User Manager 2.3.1 - 'auth.dll' pa_modify_accounts() Remote Code Execution
CVE-2012-5931—remotewindows15 nov 2012
Directory traversal vulnerability in the set_log_config function in regclnt.dll in unifid.exe in NetIQ Privileged User M
23RIESGO
abrir ↗
Metasploit600
NetIQ Privileged User Manager 2.3.1 ldapagnt_eval() Remote Perl Code Execution
CVE-2012-5932—15 nov 2012
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RIESGO
abrir ↗
Exploit-DB
Broadcom BCM4325 / BCM4329 Devices - Denial of Service
CVE-2012-2619—doshardware15 nov 2012
The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Moto
28RIESGO
abrir ↗
Metasploit600
WordPress Plugin Advanced Custom Fields Remote File Inclusion
CVE-2012-10025CRITICAL14 nov 2012
WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Myrephp Business Directory - Multiple Vulnerabilities
CVE-2012-6588—webappsphp14 nov 2012
SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Myrephp Business Directory - Multiple Vulnerabilities
CVE-2012-6589—webappsphp14 nov 2012
Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MYRE Realty Manager - Multiple Vulnerabilities
CVE-2012-6585—webappsphp14 nov 2012
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrar
23RIESGO
abrir ↗
Metasploit600
Narcissus Image Configuration Passthru Vulnerability
CVE-2012-10033CRITICAL14 nov 2012
Narcissus backend.php Image Configuration Command Injection
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
dotProject 2.1.6 - Remote File Inclusion
CVE-2006-0755MEDIUMwebappsphp14 nov 2012
Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allo
33RIESGO
abrir ↗
← anteriorpágina 1166 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.