Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Metasploit600
Open-FTPD 1.2 Arbitrary File Upload
CVE-2010-2620—18 jun 2012
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST
43RIESGO
abrir ↗
Metasploit600
IBM Lotus Notes Client URL Handler Command Injection
CVE-2012-2174—18 jun 2012
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted
50RIESGO
abrir ↗
Metasploit600
EZHomeTech EzServer Stack Buffer Overflow Vulnerability
CVE-2024-23985HIGH18 jun 2012
EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.4.3 - apache_request_headers Function Buffer Overflow (Metasploit)
CVE-2012-2329—remotewindows17 jun 2012
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote at
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MediaWiki 1.x - 'uselang' Cross-Site Scripting
CVE-2012-2698—webappsphp17 jun 2012
Cross-site scripting (XSS) vulnerability in the outputPage function in includes/SkinTemplate.php in MediaWiki before 1.1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lattice Semiconductor PAC-Designer 6.21 - Symbol Value Buffer Overflow (Metasploit)
CVE-2012-2915—localwindows17 jun 2012
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft XML Core Services - MSXML Uninitialized Memory Corruption (MS12-043) (Metasploit)
CVE-2012-1889HIGHbajo ataqueremotewindows16 jun 2012
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir ↗
Metasploit600
qdPM v7 Arbitrary PHP File Upload Vulnerability
CVE-2015-3884—14 jun 2012
Unrestricted file upload vulnerability in the (1) myAccount, (2) projects, (3) tasks, (4) tickets, (5) discussions, (6)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Myre Real Estate Mobile 2012 - Multiple Vulnerabilities
CVE-2012-4258—webappsphp14 jun 2012
Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB
ESRI ArcGIS 10.0.x / ArcMap 9 - Arbitrary Code Execution
CVE-2012-1661—localwindows14 jun 2012
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, wh
28RIESGO
abrir ↗
Exploit-DB
Adobe Illustrator CS5.5 - Memory Corruption
CVE-2012-0780—localmultiple14 jun 2012
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption)
28RIESGO
abrir ↗
Exploit-DB
Wyse - Machine Remote Power Off (Denial of Service) (Metasploit)
CVE-2009-0695—doshardware14 jun 2012
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RIESGO
abrir ↗
Exploit-DB
Wyse - Machine Remote Power Off (Denial of Service) (Metasploit)
CVE-2009-0693—doshardware14 jun 2012
Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) th
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Juniper Networks Mobility System Software - '/aaa/wba_login.html' Cross-Site Scripting
CVE-2012-1038—remotehardware14 jun 2012
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Same ID Property Deleted Object Handling Memory Corruption (MS12-037) (Metasploit)
CVE-2012-1875—remotewindows14 jun 2012
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.30 - Remote Format String Write4
CVE-2007-1195—remotewindows14 jun 2012
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple iTunes 10.6.1.7 - '.m3u' Walking Heap Buffer Overflow (PoC)
CVE-2012-0677—dosmultiple13 jun 2012
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a de
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F5 BIG-IP - SSH Private Key Exposure (Metasploit)
CVE-2012-1493—remotehardware13 jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RIESGO
abrir ↗
Metasploit300
Free Float FTP Server USER Command Buffer Overflow
CVE-2012-10023MEDIUM12 jun 2012
FreeFloat FTP Server USER Command Buffer Overflow
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F5 BIG-IP - Authentication Bypass
CVE-2012-1493—remotehardware12 jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQL - Authentication Bypass
CVE-2012-2122—remotemultiple12 jun 2012
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir ↗
Metasploit300
MS12-037 Microsoft Internet Explorer Fixed Table Col Span Heap Overflow
CVE-2012-1876—12 jun 2012
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir ↗
Metasploit300
MS12-037 Microsoft Internet Explorer Same ID Property Deleted Object Handling Memory Corruption
CVE-2012-1875—12 jun 2012
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
50RIESGO
abrir ↗
Metasploit500
FreeBSD Intel SYSRET Privilege Escalation
CVE-2012-0217—12 jun 2012
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RIESGO
abrir ↗
Metasploit400
MS12-043 Microsoft XML Core Services MSXML Uninitialized Memory Corruption
CVE-2012-1889HIGHbajo ataque12 jun 2012
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.2.8 - 'ipchange.php' Command Injection (Metasploit)
CVE-2012-0297—webappsphp12 jun 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗
Metasploit600
F5 BIG-IP SSH Private Key Exposure
CVE-2012-1493—11 jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Office - ClickOnce Unsafe Object Package Handling (MS12-005) (Metasploit)
CVE-2012-0013—localwindows11 jun 2012
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F5 BIG-IP - Authentication Bypass (PoC)
CVE-2012-1493—doshardware11 jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin wp-gpx-map 1.1.21 - Arbitrary File Upload
CVE-2012-6649—webappsphp11 jun 2012
WordPress WP GPX Maps Plugin 1.1.21 allows remote attackers to execute arbitrary PHP code via improper file upload.
28RIESGO
abrir ↗
← anteriorpágina 1180 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.