Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB✓ VexDay Proof
F5 BIG-IP - Authentication Bypass (PoC)
CVE-2012-1493—doshardware11 jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.2.8 - Arbitrary '.PHP' File Upload (Metasploit)
CVE-2012-0299—webappsphp10 jun 2012
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to u
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tom Sawyer Software GET Extension Factory - Remote Code Execution (Metasploit)
CVE-2011-2217—remotewindows10 jun 2012
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.2
50RIESGO
abrir ↗
Metasploit300
MySQL Authentication Bypass Password Dump
CVE-2012-2122—09 jun 2012
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin RBX Gallery 2.1 - Arbitrary File Upload
CVE-2012-3575—webappsphp08 jun 2012
Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attacke
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin wpStoreCart 2.5.27-2.5.29 - Arbitrary File Upload
CVE-2012-3576—webappsphp08 jun 2012
Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows re
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.14 - Remote Buffer Overflow (Metasploit)
CVE-2012-3815—remotewindows08 jun 2012
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin NewsLetter 1.5 - Remote File Disclosure
CVE-2012-3588—webappsphp08 jun 2012
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attacke
28RIESGO
abrir ↗
Metasploit400
ComSndFTP v1.3.7 Beta USER Format String (Write4) Vulnerability
CVE-2012-10055CRITICAL08 jun 2012
ComSndFTP v1.3.7 Beta USER Format String RCE
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS - MDAC 'msadcs.dll' RDS DataStub Content-Type Overflow (MS02-065) (Metasploit)
CVE-2002-1142—remotewindows08 jun 2012
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 th
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samsung NET-i viewer - Multiple ActiveX 'BackupToAvi()' Remote Overflows (Metasploit)
CVE-2012-4333—remotewindows08 jun 2012
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin FCChat Widget 2.2.x - 'upload.php' Arbitrary File Upload
CVE-2012-3578—webappsphp07 jun 2012
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lattice Semiconductor PAC-Designer 6.21 - '.PAC' Local Overflow
CVE-2012-2915—localwindows07 jun 2012
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Object File Handling Remote Code Execution (Metasploit)
CVE-2011-3400—remotewindows06 jun 2012
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RIESGO
abrir ↗
Metasploit600
Java Applet Field Bytecode Verifier Cache Remote Code Execution
CVE-2012-1723CRITICALbajo ataqueransomware06 jun 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 up
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Font Uploader 1.2.4 - Arbitrary File Upload
CVE-2012-3814—webappsphp06 jun 2012
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote
28RIESGO
abrir ↗
Metasploit300
Photodex ProShow Producer 5.0.3256 load File Handling Buffer Overflow
CVE-2012-10051HIGH06 jun 2012
Photodex ProShow Producer 5.0.3256 load File Handling Buffer Overflow
36RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
CVE-2012-3574—webappsphp06 jun 2012
Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Struts 2.2.1.1 - Remote Command Execution (Metasploit)
CVE-2012-0391CRITICALbajo ataqueremotemultiple05 jun 2012
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RIESGO
abrir ↗
Metasploit600
WordPress Plugin Foxypress uploadify.php Arbitrary Code Execution
CVE-2012-10020CRITICAL05 jun 2012
FoxyPress <= 0.4.2.1 - Arbitrary File Upload
63RIESGO
abrir ↗
Metasploit300
Sielco Sistemi Winlog Buffer Overflow 2.07.14 - 2.07.16
CVE-2012-3815—04 jun 2012
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit)
CVE-2011-4825—webappsphp03 jun 2012
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GIMP script-fu - Server Buffer Overflow (Metasploit)
CVE-2012-2763—remotewindows02 jun 2012
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RIESGO
abrir ↗
Metasploit300
IBM Lotus iNotes dwa85W ActiveX Buffer Overflow
CVE-2012-2175—01 jun 2012
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x befo
43RIESGO
abrir ↗
Exploit-DB
GIMP 2.6 script-fu < 2.8.0 - Buffer Overflow (PoC)
CVE-2012-2763—doswindows31 may 2012
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RIESGO
abrir ↗
Exploit-DB
Sony VAIO Wireless Manager 4.0.0.0 - Buffer Overflow
CVE-2012-0985—doswindows31 may 2012
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wi
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MPlayer - '.SAMI' Subtitle File Buffer Overflow (Metasploit)
CVE-2011-3625—localwindows30 may 2012
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RIESGO
abrir ↗
Metasploit600
Active Collab "chat module" Remote PHP Code Injection Exploit
CVE-2012-6554—30 may 2012
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Simple Web Content Management System 1.1 < 1.3 - Multiple SQL Injections
CVE-2012-3791—webappsphp30 may 2012
Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB
WinRadius Server 2009 - Denial of Service
CVE-2012-3816—doswindows29 may 2012
WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Requ
23RIESGO
abrir ↗
← anteriorpágina 1181 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.