Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.2.8 - Command Execution (Metasploit)
CVE-2012-0297—remotelinux28 may 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗
Metasploit600
PHP Volunteer Management System v1.0.2 Arbitrary File Upload Vulnerability
CVE-2012-10056HIGH28 may 2012
PHP Volunteer Management System 1.0.2 Arbitrary File Upload
36RIESGO
abrir ↗
Metasploit600
WordPress Asset-Manager PHP File Upload Vulnerability
CVE-2012-10026CRITICAL26 may 2012
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2012-0297—webappslinux26 may 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SocialEngine 4.2.2 - Multiple Vulnerabilities
CVE-2012-2216—webappsphp25 may 2012
20RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
appRain CMF - Arbitrary '.PHP' File Upload (Metasploit)
CVE-2012-1153—webappsphp25 may 2012
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenOffice - OLE Importer DocumentSummaryInformation Stream Handling Overflow (Metasploit)
CVE-2008-0320—localwindows25 may 2012
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of
50RIESGO
abrir ↗
Exploit-DB
Jaow 2.4.5 - Blind SQL Injection
CVE-2012-2952—webappsphp24 may 2012
SQL injection vulnerability in add_ons.php in Jaow 2.4.5 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark - Misaligned Memory Denial of Service
CVE-2012-2394—dosmultiple24 may 2012
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
CVE-2012-2392—dosmultiple24 may 2012
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
CVE-2012-3825—dosmultiple24 may 2012
Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a den
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark - DIAMETER Dissector Denial of Service
CVE-2012-2393—dosmultiple24 may 2012
epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
CVE-2012-3826—dosmultiple24 may 2012
Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a de
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Mod_Auth_OpenID - Session Stealing
CVE-2012-2760—locallinux24 may 2012
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local us
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
pragmaMx 1.12.1 - 'modules.php' URI Cross-Site Scripting
CVE-2012-2452—webappsphp23 may 2012
Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Exploit-DB
Symantec End Point Protection 11.x / Symantec Network Access Control 11.x - Local Code Execution (PoC)
CVE-2012-0289—doswindows23 may 2012
Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (S
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
pragmaMx 1.12.1 - '/includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php?img_url' Cross-Site Scripting
CVE-2012-2452—webappsphp23 may 2012
Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pligg CMS 1.x - 'module.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-2436—webappsphp23 may 2012
Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Metasploit300
IBM Lotus QuickR qp2 ActiveX Buffer Overflow
CVE-2012-2176—23 may 2012
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Plogger Photo Gallery - SQL Injection
CVE-2007-6587—webappsphp22 may 2012
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mosh - Remote Denial of Service
CVE-2012-2385—doslinux22 may 2012
The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Client 4.91 SP4 - Local Privilege Escalation
CVE-2007-5762—localwindows22 may 2012
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by open
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yandex.Server 2010 9.0 - 'text' Cross-Site Scripting
CVE-2012-2941—webappsphp21 may 2012
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP StorageWorks P4000 - Virtual SAN Appliance Command Execution (Metasploit)
CVE-2012-4361—remotehardware21 may 2012
lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to exe
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP StorageWorks P4000 - Virtual SAN Appliance Command Execution (Metasploit)
CVE-2012-2986—remotehardware21 may 2012
lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foxit Reader 3.0 - Open Execute Action Stack Buffer Overflow (Metasploit)
CVE-2009-0837—localwindows21 may 2012
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to e
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP StorageWorks P4000 - Virtual SAN Appliance Command Execution (Metasploit)
CVE-2012-4362—remotehardware21 may 2012
hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vanilla Forums About Me Plugin - Persistent Cross-Site Scripting
CVE-2012-6557—webappsphp21 may 2012
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Real-DRAW PRO 5.2.4 - Import File Crash
CVE-2012-2940—doswindows21 may 2012
MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vanilla FirstLastNames 1.3.2 Plugin - Persistent Cross-Site Scripting
CVE-2012-6556—webappsphp21 may 2012
Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote a
23RIESGO
abrir ↗
← anteriorpágina 1182 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.