Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.523exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
Metasploit600
WordPress WP-Property PHP File Upload Vulnerability
CVE-2012-10027CRITICAL26 mar 2012
WordPress Plugin WP-Property <= 1.35.0 PHP File Upload
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ricoh DC Software DL-10 SR10 FTP Server (SR10.exe) - FTP USER Command Buffer Overflow (Metasploit)
CVE-2012-5002—remotewindows24 mar 2012
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file
50RIESGO
abrir ↗
Exploit-DB
RealPlayer - '.mp4' file handling memory Corruption
CVE-2012-1904—doswindows24 mar 2012
mp4fformat.dll in the QuickTime File Format plugin in RealNetworks RealPlayer 15 and earlier, and RealPlayer SP 1.1.4 Bu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreePBX 2.9.0/2.10.0 - 'callmenum' Remote Code Execution (Metasploit)
CVE-2012-4869—webappsphp24 mar 2012
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir ↗
Exploit-DB
Sitecom WLM-2501 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-1922—webappsasp23 mar 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the auth
23RIESGO
abrir ↗
Exploit-DB
Wolfcms 0.75 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2012-1898—webappsphp23 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Struts 2.0 - 'XSLTResult.java' Arbitrary File Upload
CVE-2012-1592—webappsjava23 mar 2012
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreePBX 2.10.0 / Elastix 2.2.0 - Remote Code Execution
CVE-2012-4869—webappsphp23 mar 2012
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir ↗
Exploit-DB
Wolfcms 0.75 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2012-1897—webappsphp23 mar 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack
23RIESGO
abrir ↗
Exploit-DB
Sitecom WLM-2501 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-1921—webappsasp23 mar 2012
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker
23RIESGO
abrir ↗
Metasploit300
FlexNet License Server Manager lmgrd Buffer Overflow
CVE-2011-4135—23 mar 2012
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Man
30RIESGO
abrir ↗
Metasploit400
TFM MMPlayer (m3u/ppl File) Buffer Overflow
CVE-2009-2566—23 mar 2012
Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary cod
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreePBX 2.9.0/2.10.0 - Multiple Vulnerabilities
CVE-2012-4870—webappsphp22 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Memory Use-After-Free (MS10-002) (Metasploit)
CVE-2010-0248HIGHremotewindows22 mar 2012
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers
68RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ricoh DC Software DL-10 SR10 FTP Server (SR10.exe) 1.1.0.6 - Remote Buffer Overflow
CVE-2012-5002—doswindows22 mar 2012
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Grade Book 1.9.4 - SQL Database Export
CVE-2012-1670—webappsphp22 mar 2012
admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreePBX 2.9.0/2.10.0 - Multiple Vulnerabilities
CVE-2012-4869—webappsphp22 mar 2012
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMoneyBooks 1.0.2 - Local File Inclusion
CVE-2012-1669—webappsphp22 mar 2012
Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and exec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ricoh DC Software DL-10 SR10 FTP Server (SR10.exe) 1.1.0.6 - Remote Buffer Overflow
CVE-2015-6750—doswindows22 mar 2012
Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera PlayerPT - ActiveX Control PlayerPT.ocx sprintf Buffer Overflow (PoC)
CVE-2012-0284—doswindows22 mar 2012
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.o
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vBShout - Persistent Cross-Site Scripting
CVE-2012-6667—webappsphp22 mar 2012
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows r
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMoneyBooks 1.0.2 - Local File Inclusion
CVE-2012-6665—webappsphp22 mar 2012
Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files vi
23RIESGO
abrir ↗
Metasploit300
Cisco Linksys PlayerPT ActiveX Control Buffer Overflow
CVE-2012-0284—22 mar 2012
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.o
50RIESGO
abrir ↗
Exploit-DB
Oreans WinLicense 2.1.8.0 - XML File Handling Memory Corruption
CVE-2012-4864—doswindows21 mar 2012
Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibl
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Journal Systems (OJS) 2.3.6 - 'index.php?authors[][url]' Cross-Site Scripting
CVE-2012-1469—webappsphp21 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpList 2.10.17 - SQL Injection / Cross-Site Scripting
CVE-2012-2741—webappsphp21 mar 2012
Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Journal Systems (OJS) 2.3.6 - Multiple Script Arbitrary File Upload
CVE-2012-1468—webappsphp21 mar 2012
Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Autho
23RIESGO
abrir ↗
Exploit-DB
Oreans Themida 2.1.8.0 - '.TMD' File Handling Buffer Overflow
CVE-2012-4865—doswindows21 mar 2012
Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Journal Systems (OJS) 2.3.6 - '/lib/pkp/classes/core/String.inc.php?String::stripUnsafeHtml()' Method Cross-Site Scripting
CVE-2012-1469—webappsphp21 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Journal Systems (OJS) 2.3.6 - 'rfiles.php' Traversal Arbitrary File Manipulation
CVE-2012-1467—webappsphp21 mar 2012
Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.
23RIESGO
abrir ↗
← anteriorpágina 1193 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.