Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB
Oracle WebCenter Sites (FatWire Content Server) - Multiple Vulnerabilities
CVE-2012-3185—webappsmultiple17 oct 2012
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 6.1, 6.2, 6.3.x, 7, 7.0.1,
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ModSecurity - 'POST' Security Bypass
CVE-2012-4528—remotelinux17 oct 2012
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver ar
28RIESGO
abrir ↗
Metasploit300
Drupal OpenID External Entity Injection
CVE-2012-4554—17 oct 2012
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE d
23RIESGO
abrir ↗
Metasploit600
Java Applet Method Handle Remote Code Execution
CVE-2012-5088—16 oct 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
60RIESGO
abrir ↗
Metasploit600
Java Applet JAX-WS Remote Code Execution
CVE-2012-5076CRITICALbajo ataque16 oct 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RIESGO
abrir ↗
Metasploit600
Ektron 8.02 XSLT Transform Remote Code Execution
CVE-2012-5357—16 oct 2012
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true
50RIESGO
abrir ↗
Metasploit600
Sun Java Web Start Double Quote Injection
CVE-2012-1533—16 oct 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and
50RIESGO
abrir ↗
Metasploit600
Java Applet AverageRangeStatisticImpl Remote Code Execution
CVE-2012-5076CRITICALbajo ataque16 oct 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RIESGO
abrir ↗
Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
CVE-2012-3808—remotewindows16 oct 2012
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
23RIESGO
abrir ↗
Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
CVE-2012-3810—remotewindows16 oct 2012
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
23RIESGO
abrir ↗
Exploit-DB
EZHomeTech EzServer 7.0 - Remote Heap Corruption
CVE-2012-4750—doswindows16 oct 2012
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, wh
23RIESGO
abrir ↗
Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
CVE-2012-3809—remotewindows16 oct 2012
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
23RIESGO
abrir ↗
Exploit-DB
Samsung Kies 2.3.2.12054_20 - Multiple Vulnerabilities
CVE-2012-3807—remotewindows16 oct 2012
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
35RIESGO
abrir ↗
Exploit-DB
Huawei Technologies Internet Mobile - Unicode (SEH)
CVE-2012-6568—localwindows15 oct 2012
Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN
23RIESGO
abrir ↗
Metasploit500
Windows Escalate Service Permissions Local Privilege Escalation
CVE-2025-21293HIGH15 oct 2012
Active Directory Domain Services Elevation of Privilege Vulnerability
41RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
CVE-2012-5470—doswindows11 oct 2012
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash
23RIESGO
abrir ↗
Metasploit300
MS11-081 Microsoft Internet Explorer Option Element Use-After-Free
CVE-2011-1996—11 oct 2012
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Excel - Denial of Service
CVE-2012-5672—doswindows11 oct 2012
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cau
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KeyHelp - ActiveX LaunchTriPane Remote Code Execution (Metasploit)
CVE-2012-2516—remotewindows11 oct 2012
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Pl
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenX 2.8.10 - 'plugin-index.php' Cross-Site Scripting
CVE-2012-4989—webappsphp10 oct 2012
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - 'AfdJoinLeaf' Local Privilege Escalation (MS11-080) (Metasploit)
CVE-2011-2005HIGHbajo ataquelocalwindows10 oct 2012
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel UDEV < 1.4.1 - 'Netlink' Local Privilege Escalation (Metasploit)
CVE-2009-1185—locallinux10 oct 2012
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NTR - ActiveX Control 'Check()' Method Buffer Overflow (Metasploit)
CVE-2012-0266—remotewindows10 oct 2012
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMyAdmin 3.5.2.2 - 'server_sync.php' Backdoor (Metasploit)
CVE-2012-5159—webappsphp10 oct 2012
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an e
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Avaya IP Office Customer Call Reporter - 'ImageUpload.ashx' Remote Command Execution (Metasploit)
CVE-2012-3811—remotewindows10 oct 2012
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Webmin 1.580 - '/file/show.cgi' Remote Command Execution (Metasploit)
CVE-2012-2982—remoteunix10 oct 2012
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samba 3.4.16/3.5.14/3.6.4 - SetInformationPolicy AuditEventsInfo Heap Overflow (Metasploit)
CVE-2012-1182—remotelinux10 oct 2012
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement valida
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
InduSoft Web Studio - Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2011-4051—remotewindows10 oct 2012
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NTR - ActiveX Control 'StopModule()' Remote Code Execution (Metasploit)
CVE-2012-0267—remotewindows10 oct 2012
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - execCommand Use-After-Free (MS12-063) (Metasploit)
CVE-2012-4969HIGHbajo ataqueremotewindows10 oct 2012
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al
100RIESGO
abrir ↗
← anteriorpágina 1169 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.