Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB✓ VexDay Proof
MYRE Realty Manager - Multiple Vulnerabilities
CVE-2012-6584—webappsphp14 nov 2012
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MYREphp Vacation Rental Software - Multiple Vulnerabilities
CVE-2012-6587—webappsphp14 nov 2012
Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows
23RIESGO
abrir ↗
Metasploit600
Narcissus Image Configuration Passthru Vulnerability
CVE-2012-10033CRITICAL14 nov 2012
Narcissus backend.php Image Configuration Command Injection
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet - JAX-WS Remote Code Execution (Metasploit)
CVE-2012-5067—remotemultiple13 nov 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Huawei (Multiple Products) - Password Encryption
CVE-2012-4960—remotehardware13 nov 2012
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Invision Power Board (IP.Board) 3.3.4 - 'Unserialize()' PHP Code Execution (Metasploit)
CVE-2012-5692—remotephp13 nov 2012
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IrfanView - '.TIF' Image Decompression Buffer Overflow
CVE-2009-5022—doswindows13 nov 2012
Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execut
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet - JAX-WS Remote Code Execution (Metasploit)
CVE-2012-5076CRITICALbajo ataqueremotemultiple13 nov 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ESRI ArcGIS for Server - 'where' SQL Injection
CVE-2012-4949—webappsmultiple09 nov 2012
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AR Web Content Manager (AWCM) - 'cookie_gen.php' Arbitrary Cookie Generation
CVE-2012-2437—webappsphp08 nov 2012
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to ge
23RIESGO
abrir ↗
Metasploit300
VMWare OVF Tools Format String Vulnerability
CVE-2012-3569—08 nov 2012
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RIESGO
abrir ↗
Metasploit300
VMWare OVF Tools Format String Vulnerability
CVE-2012-3569—08 nov 2012
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RIESGO
abrir ↗
Metasploit300
Apple QuickTime 7.7.2 MIME Type Buffer Overflow
CVE-2012-3753—07 nov 2012
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RIESGO
abrir ↗
Metasploit300
Apple QuickTime 7.7.2 TeXML Style Element font-table Field Stack Buffer Overflow
CVE-2012-3752—07 nov 2012
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RIESGO
abrir ↗
Exploit-DB
Invision Power Board (IP.Board) 3.3.4 - Unserialize Regex Bypass
CVE-2012-5692—webappsphp07 nov 2012
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OrangeHRM - 'sortField' SQL Injection
CVE-2012-5367—webappsphp07 nov 2012
Multiple SQL injection vulnerabilities in OrangeHRM 2.7.1 RC 1 allow remote authenticated administrators to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cryptocat 2.0.22 - Arbitrary Script Injection
CVE-2013-4103—remotemultiple07 nov 2012
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EMC NetWorker - Format String (Metasploit)
CVE-2012-2288—remotewindows07 nov 2012
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cryptocat 2.0.21 Chrome Extension - 'img/keygen.gif' File Information Disclosure
CVE-2013-2261—remotemultiple07 nov 2012
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VeriCentre - Multiple SQL Injections
CVE-2012-4951—webappsphp06 nov 2012
Multiple SQL injection vulnerabilities in terminal/paramedit.aspx in VeriFone VeriCentre Web Console before 2.2 build 36
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
CVE-2012-5684—webappsmultiple05 nov 2012
Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
CVE-2012-5685—webappsmultiple05 nov 2012
SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
CVE-2012-5686—webappsmultiple05 nov 2012
ZPanel 10.0.1 has insufficient entropy for its password reset process.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZPanel 10.0.1 - Cross-Site Request Forgery / Cross-Site Scripting / SQL Injection / Password Reset
CVE-2012-5683—webappsmultiple05 nov 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack
23RIESGO
abrir ↗
Metasploit300
XBMC Web Server Directory Traversal
CVE-2012-10024HIGH04 nov 2012
XBMC ≤ 11.0 Web Server Path Traversal
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin All Video Gallery 1.1 - SQL Injection
CVE-2012-6653—webappsphp02 nov 2012
Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified
23RIESGO
abrir ↗
Exploit-DB
SIEMENS Sipass Integrated 2.6 Ethernet Bus - Arbitrary Pointer Dereference
CVE-2012-5409—doswindows01 nov 2012
AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages r
28RIESGO
abrir ↗
Exploit-DB
Konqueror 4.7.3 - Memory Corruption
CVE-2012-4515—doslinux01 nov 2012
Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is
23RIESGO
abrir ↗
Exploit-DB
Konqueror 4.7.3 - Memory Corruption
CVE-2012-4512—doslinux01 nov 2012
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Invision Power Board (IP.Board) 3.3.4 - 'Unserialize()' PHP Code Execution
CVE-2012-5692—webappsphp01 nov 2012
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RIESGO
abrir ↗
← anteriorpágina 1167 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.