Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Metasploit600
KeyHelp ActiveX LaunchTriPane Remote Code Execution Vulnerability
CVE-2012-2516—26 jun 2012
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Pl
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SugarCRM CE 6.3.1 - 'Unserialize()' PHP Code Execution (Metasploit)
CVE-2012-0694—webappsphp26 jun 2012
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Slimpdf Reader 1.0 - Memory Corruption
CVE-2011-4220—doswindows25 jun 2012
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Able2Doc and Able2Doc Professional 6.0 - Memory Corruption
CVE-2011-4220—doswindows25 jun 2012
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iTunes 10 - Extended M3U Stack Buffer Overflow (Metasploit)
CVE-2012-0677—remotewindows25 jun 2012
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a de
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Able2Extract and Able2Extract Server 6.0 - Memory Corruption
CVE-2011-4221—doswindows25 jun 2012
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a deni
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Able2Doc and Able2Doc Professional 6.0 - Memory Corruption
CVE-2011-4221—doswindows25 jun 2012
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a deni
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player - Object Type Confusion (Metasploit)
CVE-2012-0779—remotewindows25 jun 2012
Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Slimpdf Reader 1.0 - Memory Corruption
CVE-2011-4222—doswindows25 jun 2012
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a de
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kingview Touchview 6.53 - EIP Overwrite
CVE-2012-1830—doswindows25 jun 2012
Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Able2Extract and Able2Extract Server 6.0 - Memory Corruption
CVE-2011-4222—doswindows25 jun 2012
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a de
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FCKEditor Core - 'Editor 'spellchecker.php' Cross-Site Scripting
CVE-2012-4000—webappsphp25 jun 2012
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerp
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Able2Extract and Able2Extract Server 6.0 - Memory Corruption
CVE-2011-4220—doswindows25 jun 2012
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kingview Touchview 6.53 - Multiple Heap Overflow Vulnerabilities
CVE-2012-1831—doswindows25 jun 2012
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Able2Doc and Able2Doc Professional 6.0 - Memory Corruption
CVE-2011-4222—doswindows25 jun 2012
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a de
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Slimpdf Reader 1.0 - Memory Corruption
CVE-2011-4221—doswindows25 jun 2012
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a deni
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Parodia 6.8 - 'employer-profile.asp' SQL Injection
CVE-2011-2751—webappsasp25 jun 2012
SQL injection vulnerability in Parodia before 6.809 allows remote attackers to execute arbitrary SQL commands via unspec
23RIESGO
abrir ↗
Metasploit600
SugarCRM unserialize() PHP Code Execution
CVE-2012-0694—23 jun 2012
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lattice Diamond Programmer 1.4.2 - Buffer Overflow (PoC)
CVE-2012-2614—doswindows22 jun 2012
Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a d
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XnView 1.98.8 - '.gif' Image Processing Heap Overflow
CVE-2012-0282—doswindows22 jun 2012
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XnView 1.98.8 - '.tiff' Image Processing Heap Overflow (1)
CVE-2012-0276—doswindows22 jun 2012
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XnView 1.98.8 - '.tiff' Image Processing Heap Overflow (2)
CVE-2012-0276—doswindows22 jun 2012
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XnView 1.98.8 - '.PCT' Image Processing Heap Overflow
CVE-2012-0277—doswindows22 jun 2012
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash
23RIESGO
abrir ↗
Exploit-DB
IBM System Storage DS Storage Manager Profiler - Multiple Vulnerabilities
CVE-2012-2172—webappswindows21 jun 2012
Cross-site scripting (XSS) vulnerability in SoftwareRegistration.do in the Storage Manager Profiler in IBM System Storag
23RIESGO
abrir ↗
Exploit-DB
IBM System Storage DS Storage Manager Profiler - Multiple Vulnerabilities
CVE-2012-2171—webappswindows21 jun 2012
SQL injection vulnerability in ModuleServlet.do in the Storage Manager Profiler in IBM System Storage DS Storage Manager
23RIESGO
abrir ↗
Metasploit500
Adobe Flash Player AVM Verification Logic Array Indexing Code Execution
CVE-2011-2110—21 jun 2012
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android,
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player - AVM Verification Logic Array Indexing Code Execution (Metasploit)
CVE-2008-4192—remotewindows20 jun 2012
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
web@all - Cross-Site Scripting
CVE-2012-3232—webappsphp20 jun 2012
Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player - AVM Verification Logic Array Indexing Code Execution (Metasploit)
CVE-2011-2110—remotewindows20 jun 2012
Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android,
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Data Protector Client - EXEC_CMD Remote Code Execution
CVE-2011-0922—remotewindows19 jun 2012
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RIESGO
abrir ↗
← anteriorpágina 1179 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.