Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB
OTRS Open Technology Real Services 3.1.8/3.1.9 - Cross-Site Scripting
CVE-2012-4751—webappswindows31 ago 2012
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Download Monitor - 'dlsearch' Cross-Site Scripting
CVE-2012-4768—webappsphp30 ago 2012
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attac
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Crowbar - 'file' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-3551—webappsphp30 ago 2012
Cross-site scripting (XSS) vulnerability in crowbar_framework/app/views/support/index.html.haml in the Crowbar barclamp
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Messaging Gateway 9.5/9.5.1 - SSH Default Password Security Bypass (Metasploit)
CVE-2012-3579—remotelinux30 ago 2012
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RIESGO
abrir ↗
Metasploit400
HP SiteScope Remote Code Execution
CVE-2012-3260—29 ago 2012
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbit
30RIESGO
abrir ↗
Metasploit400
HP SiteScope Remote Code Execution
CVE-2012-3261—29 ago 2012
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbit
30RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Intelligent Management Center < 5.0 E0102 - UAM Buffer Overflow (Metasploit)
CVE-2012-3274—localwindows29 ago 2012
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (I
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PrestaShop 1.4.7 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-2517—webappsphp29 ago 2012
Cross-site scripting (XSS) vulnerability in PrestaShop before 1.4.9 allows remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Phorum 5.2.18 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-4234—webappsphp29 ago 2012
Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum be
23RIESGO
abrir ↗
Metasploit300
EMC Networker Format String
CVE-2012-2288—29 ago 2012
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.
50RIESGO
abrir ↗
Metasploit300
HP Intelligent Management Center UAM Buffer Overflow
CVE-2012-3274—29 ago 2012
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (I
50RIESGO
abrir ↗
Metasploit300
ActiveFax (ActFax) 4.3 Client Importer Buffer Overflow
CVE-2012-10043CRITICAL28 ago 2012
ActFax 4.32 Client Importer Buffer Overflow
43RIESGO
abrir ↗
Metasploit600
Symantec Messaging Gateway 9.5 Default SSH Password Vulnerability
CVE-2012-3579—27 ago 2012
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Rational ClearQuest 8.0 - Multiple Vulnerabilities
CVE-2012-0744—webappsphp27 ago 2012
IBM Rational ClearQuest 7.1.x through 7.1.2.7 and 8.x through 8.0.0.3 allows remote attackers to obtain potentially sens
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Intel x64 SYSRET (MS12-042)
CVE-2012-0217—localwindows_x86-6427 ago 2012
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java 7 Applet - Remote Code Execution (Metasploit)
CVE-2012-0547—remotejava27 ago 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier, and
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Zabbix Server - Arbitrary Command Execution (Metasploit)
CVE-2009-4498—remotelinux27 ago 2012
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java 7 Applet - Remote Code Execution (Metasploit)
CVE-2012-3539—remotejava27 ago 2012
20RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java 7 Applet - Remote Code Execution (Metasploit)
CVE-2012-4681CRITICALbajo ataqueransomwareremotejava27 ago 2012
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir ↗
Metasploit600
Java 7 Applet Remote Code Execution
CVE-2012-4681CRITICALbajo ataqueransomware26 ago 2012
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir ↗
Exploit-DB
letodms 3.3.6 - Multiple Vulnerabilities
CVE-2012-4384—webappsphp23 ago 2012
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Cale
23RIESGO
abrir ↗
Exploit-DB
letodms 3.3.6 - Multiple Vulnerabilities
CVE-2012-4385—webappsphp23 ago 2012
letodms 3.3.6 has CSRF via change password
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Websense Content Gateway - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-2984—remotemultiple23 ago 2012
Multiple cross-site scripting (XSS) vulnerabilities in monitor/m_overview.ink in Websense Content Gateway before 7.7.3 a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
CVE-2012-2511—dosmultiple21 ago 2012
The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
CVE-2012-2514—dosmultiple21 ago 2012
The DiagiEventSource function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver
23RIESGO
abrir ↗
Metasploit600
XODA 0.4.5 Arbitrary PHP File Upload Vulnerability
CVE-2012-10045CRITICAL21 ago 2012
XODA 0.4.5 Arbitrary PHP File Upload
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
CVE-2012-2612—dosmultiple21 ago 2012
The DiagTraceHex function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher 7.0 ehp1/2 - Multiple Vulnerabilities
CVE-2012-2512—dosmultiple21 ago 2012
The DiagTraceStreamI function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.3.18 - Arbitrary Password Change
CVE-2012-2977—webappslinux21 ago 2012
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwor
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.3.18 - Arbitrary Password Change (Metasploit)
CVE-2012-2977—webappslinux21 ago 2012
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwor
23RIESGO
abrir ↗
← anteriorpágina 1172 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.