Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
81.453 exploits
Exploit-DB✓ VexDay Proof
WebCalendar 1.2.4 - Remote Code Injection (Metasploit)
CVE-2012-1495—webappslinux29 abr 2012
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
CVE-2012-3834—webappsphp29 abr 2012
SQL injection vulnerability in forensics/base_qry_main.php in AlienVault Open Source Security Information Management (OS
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
CVE-2012-3835—webappsphp29 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 3.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Alienvault Open Source SIEM (OSSIM) 3.1 - Multiple Vulnerabilities
CVE-2012-2599—webappsphp29 abr 2012
20RIESGO
abrir ↗
Metasploit300
InduSoft Web Studio ISSymbol.ocx InternationalSeparator() Heap Overflow
CVE-2011-0340—28 abr 2012
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'install.php?language' Traversal Arbitrary File Access
CVE-2012-4253—webappsperl27 abr 2012
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nokia PC Suite Video Manager 7.1.180.64 - '.mp4' Denial of Service
CVE-2012-2442—doswindows27 abr 2012
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'sql.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-4251—webappsphp27 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CPE17 Autorun Killer 1.7.1 - Local Stack Buffer Overflow (Metasploit)
CVE-2012-4054—localwindows27 abr 2012
Buffer overflow in the readfile function in CPE17 Autorun Killer 1.7.1 and earlier allows physically proximate attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'filemanagement.php?f' Traversal Arbitrary File Access
CVE-2012-4253—webappsphp27 abr 2012
Multiple directory traversal vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to read arbitrary files via a
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'install.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-4251—webappsphp27 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'index.php?page' Cross-Site Scripting
CVE-2012-4251—webappsphp27 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB
WordPress Core 3.3.1 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-1936—webappsphp27 abr 2012
The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XM Forum - 'id' Multiple SQL Injections
CVE-2012-4060—webappsasp27 abr 2012
Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Uiga FanClub - 'p' SQL Injection
CVE-2012-4055—webappsphp27 abr 2012
SQL injection vulnerability in index2.php in Uiga Fan Club allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'main.php' Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-4252—webappsphp27 abr 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to hijack the au
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - Multiple Script Direct Request Information Disclosures
CVE-2012-4254—webappsphp27 abr 2012
MySQLDumper 1.24.4 allows remote attackers to obtain sensitive information (Notices) via a direct request to (1) learn/c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MySQLDumper 1.24.4 - 'restore.php?Filename' Cross-Site Scripting
CVE-2012-4251—webappsphp27 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in MySQLDumper 1.24.4 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Volunteer management 1.0.2 - Multiple Vulnerabilities
CVE-2012-6504—webappsphp26 abr 2012
SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
gpEasy 2.3.3 - 'jsoncallback' Cross-Site Scripting
CVE-2012-6513—webappsphp26 abr 2012
Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to i
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Zingiri Web Shop 2.4.0 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-6506—webappsphp26 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in the Zingiri Web Shop plugin 2.4.0 for WordPress allow remote atta
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Volunteer management 1.0.2 - Multiple Vulnerabilities
CVE-2012-6505—webappsphp26 abr 2012
Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mount.cifs - 'chdir()' Arbitrary Root File Identification
CVE-2012-1586—locallinux25 abr 2012
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the fil
23RIESGO
abrir ↗
Exploit-DB
piwigo 2.3.3 - Multiple Vulnerabilities
CVE-2012-2209—webappsphp25 abr 2012
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in Piwigo before 2.3.4 allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB
piwigo 2.3.3 - Multiple Vulnerabilities
CVE-2012-2208—webappsphp25 abr 2012
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Shadow Stream Recorder 3.0.1.7 - Local Buffer Overflow (Metasploit)
CVE-2009-1642—localwindows25 abr 2012
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - MSCOMCTL ActiveX Buffer Overflow (MS12-027) (Metasploit)
CVE-2012-0158HIGHbajo ataqueransomwareremotewindows25 abr 2012
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RIESGO
abrir ↗
Exploit-DB
RuggedCom Devices - Backdoor Access
CVE-2012-1803—remotehardware24 abr 2012
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Ad
50RIESGO
abrir ↗
Exploit-DB
RuggedCom Devices - Backdoor Access
CVE-2012-2441—remotehardware24 abr 2012
RuggedCom Rugged Operating System (ROS) before 3.3 has a factory account with a password derived from the MAC Address fi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Ticket System Beta 1 - 'index.php?p' SQL Injection
CVE-2012-6516—webappsphp24 abr 2012
SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
← anteriorpágina 1187 / 2716siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.