Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
Exploit-DB✓ VexDay Proof
Wikidforum 2.10 - Advanced Search Multiple Field SQL Injections
CVE-2012-6520—webappsphp12 mar 2012
Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB
GOM Media Player 2.1.37 - Buffer Overflow
CVE-2012-1774—doswindows12 mar 2012
Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Litespeed Web Server - 'gtitle' Cross-Site Scripting
CVE-2012-4871—remotemultiple12 mar 2012
Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wikidforum 2.10 - Search Field Cross-Site Scripting
CVE-2012-2099—webappsphp12 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CreateVision CMS - 'id' SQL Injection
CVE-2012-1778—webappsphp11 mar 2012
SQL injection vulnerability in artykul_print.php in CreateVision CMS allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Exploit-DB
PHP Address Book 6.2.12 - Multiple Vulnerabilities
CVE-2008-2565—webappsphp10 mar 2012
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB
PHP Address Book 6.2.12 - Multiple Vulnerabilities
CVE-2012-2903—webappsphp10 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject
23RIESGO
abrir ↗
Exploit-DB
PHP Address Book 6.2.12 - Multiple Vulnerabilities
CVE-2008-2566—webappsphp10 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RIESGO
abrir ↗
Exploit-DB
PHP Address Book 6.2.12 - Multiple Vulnerabilities
CVE-2012-1911—webappsphp10 mar 2012
Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Exploit-DB
PHP Address Book 6.2.12 - Multiple Vulnerabilities
CVE-2012-1912—webappsphp10 mar 2012
Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers
23RIESGO
abrir ↗
Exploit-DB
PyPAM Python bindings for PAM - Double-Free Corruption
CVE-2012-1502—doslinux10 mar 2012
Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a
28RIESGO
abrir ↗
Exploit-DB
RazorCMS 1.2.1 Stable - Cross-Site Request Forgery (Delete Web Pages)
CVE-2012-1900—webappsphp08 mar 2012
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player - '.mp4 cprt' Remote Overflow (Metasploit)
CVE-2012-0754HIGHbajo ataqueremotewindows08 mar 2012
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OSClass 2.3.x - Directory Traversal / Arbitrary File Upload
CVE-2012-1617—webappsphp07 mar 2012
Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbit
23RIESGO
abrir ↗
Exploit-DB
promise webpam 2.2.0.13 - Multiple Vulnerabilities
CVE-2006-2758—webappsphp07 mar 2012
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %
23RIESGO
abrir ↗
Exploit-DB
promise webpam 2.2.0.13 - Multiple Vulnerabilities
CVE-2005-3747—webappsphp07 mar 2012
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly inv
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HomeSeer HS2 and HomeSeer PRO - Multiple Vulnerabilities
CVE-2011-4837—webappswindows07 mar 2012
Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HomeSeer HS2 and HomeSeer PRO - Multiple Vulnerabilities
CVE-2011-4835—webappswindows07 mar 2012
Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitr
23RIESGO
abrir ↗
Metasploit300
NetDecision NOCVision Server Directory Traversal
CVE-2012-1465—07 mar 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open Realty 2.5.x - 'select_users_template' Local File Inclusion
CVE-2012-1112—webappsphp05 mar 2012
Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! 2.5.1 - 'redirect.php' Blind SQL Injection
CVE-2012-1116—webappsphp05 mar 2012
SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Etano 1.20/1.22 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-1110—webappsphp05 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Etano 1.20/1.22 - 'photo_view.php?return' Cross-Site Scripting
CVE-2012-1110—webappsphp05 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Etano 1.20/1.22 - 'photo_search.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-1110—webappsphp05 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB
DZCP (deV!L_z Clanportal) Witze Addon 0.9 - SQL Injection
CVE-2012-5000—webappsphp04 mar 2012
SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to
23RIESGO
abrir ↗
Exploit-DB
AneCMS 2e2c583 - Local File Inclusion
CVE-2012-4997—webappsphp04 mar 2012
Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗
Exploit-DB
Rivettracker 1.03 - Multiple SQL Injections
CVE-2012-4996—webappsmultiple03 mar 2012
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB
Timesheet Next Gen 1.5.2 - Multiple SQL Injections
CVE-2012-2105—webappsphp03 mar 2012
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Exploit-DB
FlashFXP 4.1.8.1701 - Remote Buffer Overflow
CVE-2012-4992—remotewindows03 mar 2012
Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via
28RIESGO
abrir ↗
Exploit-DB
Rivettracker 1.03 - Multiple SQL Injections
CVE-2012-4993—webappsmultiple03 mar 2012
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers
23RIESGO
abrir ↗
← anteriorpágina 1195 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.