Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
Exploit-DB✓ VexDay Proof
Open Journal Systems (OJS) 2.3.6 - 'index.php?authors[][url]' Cross-Site Scripting
CVE-2012-1469—webappsphp21 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Photoshop 12.1 - '.tiff' Parsing Use-After-Free
CVE-2012-2027—doswindows20 mar 2012
Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote atta
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNUBoard 4.34.20 - 'download.php' HTML Injection
CVE-2012-4873—webappsphp20 mar 2012
Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard before 4.34.21 allows remote attacker
23RIESGO
abrir ↗
Metasploit0
FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution
CVE-2012-4869—20 mar 2012
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LANDesk Lenovo ThinkManagement Suite 9.0.3 Core Server - Arbitrary File Deletion
CVE-2012-1196—remotewindows19 mar 2012
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagemen
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LANDesk Lenovo ThinkManagement Suite 9.0.3 - Core Server Remote Code Execution
CVE-2012-1195—remotewindows19 mar 2012
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
2X ApplicationServer 10.1 - TuxSystem Class ActiveX Control Remote File Overwrite
CVE-2012-1065—remotewindows19 mar 2012
Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 12
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.1 - 'APPE' Remote Buffer Overflow
CVE-2012-5329—doswindows19 mar 2012
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pre Printing Press - 'product_desc.php?pid' SQL Injection
CVE-2012-5334—webappsphp18 mar 2012
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebGlimpse 2.x - 'wgarcmin.cgi' Full Path Disclosure
CVE-2009-5112—webappscgi18 mar 2012
wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted requ
23RIESGO
abrir ↗
Exploit-DB
TYPSoft FTP Server 1.1 - 'APPE' Remote Denial of Service
CVE-2012-5329—doswindows17 mar 2012
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PRE PRINTING STUDIO - SQL Injection
CVE-2012-5333—webappsphp17 mar 2012
SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB
ASP Classifieds - SQL Injection
CVE-2007-2675—webappsphp17 mar 2012
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tiny Server 1.1.5 - Arbitrary File Disclosure
CVE-2012-5335—remotewindows16 mar 2012
Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Terminal Services - Use-After-Free (MS12-020)
CVE-2012-0002—doswindows16 mar 2012
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FlexCMS 3.2.1 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-1901—webappsphp16 mar 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in FlexCMS 3.2.1 and earlier allow remote attackers to (1) hi
23RIESGO
abrir ↗
Metasploit300
MS12-020 Microsoft Remote Desktop Use-After-Free DoS
CVE-2012-0002—16 mar 2012
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RIESGO
abrir ↗
Exploit-DB
Asterisk - 'ast_parse_digest()' Stack Buffer Overflow (PoC)
CVE-2012-1184—doslinux15 mar 2012
Stack-based buffer overflow in the ast_parse_digest function in main/utils.c in Asterisk 1.8.x before 1.8.10.1 and 10.x
28RIESGO
abrir ↗
Metasploit300
VLC MMS Stream Handling Buffer Overflow
CVE-2012-1775—15 mar 2012
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netmechanica NetDecision HTTP Server 4.5.1 - Remote Buffer Overflow (Metasploit)
CVE-2012-1465—remotewindows15 mar 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir ↗
Exploit-DB
asaanCart - Cross-Site Scripting / Local File Inclusion
CVE-2012-5331—webappsphp14 mar 2012
Directory traversal vulnerability in asaanCart 0.9 allows remote attackers to include arbitrary local files via a .. (do
23RIESGO
abrir ↗
Exploit-DB
Sitecom WLM-2501 - Cross-Site Request Forgery
CVE-2012-1922—webappshardware14 mar 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the auth
23RIESGO
abrir ↗
Exploit-DB
asaanCart - Cross-Site Scripting / Local File Inclusion
CVE-2012-5330—webappsphp14 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in asaanCart 0.9 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
Metasploit300
Sockso Music Host Server 1.5 Directory Traversal
CVE-2012-10061HIGH14 mar 2012
Sockso Music Host Server <= 1.5 Path Traversal
36RIESGO
abrir ↗
Exploit-DB
Sitecom WLM-2501 - Cross-Site Request Forgery
CVE-2012-1921—webappshardware14 mar 2012
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker
23RIESGO
abrir ↗
Exploit-DB
PBLang Bulletin Board System - Local File Inclusion
CVE-2005-2892—webappsphp13 mar 2012
Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
LightDM 1.0.6 - Arbitrary File Deletion
CVE-2012-0943—locallinux13 mar 2012
debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Lin
23RIESGO
abrir ↗
Metasploit300
HP Data Protector Create New Folder Buffer Overflow
CVE-2012-0124—12 mar 2012
Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Synology Photo Station 5 DSM 3.2 - 'photo_one.php' Script Cross-Site Scripting
CVE-2012-1556—webappsphp12 mar 2012
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Litespeed Web Server - 'gtitle' Cross-Site Scripting
CVE-2012-4871—remotemultiple12 mar 2012
Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.
23RIESGO
abrir ↗
← anteriorpágina 1194 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.