Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
Exploit-DB✓ VexDay Proof
starCMS - 'q' URI Cross-Site Scripting
CVE-2012-4998—webappsphp02 mar 2012
Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DJ Studio Pro 5.1 - '.pls' Local Stack Buffer Overflow (Metasploit)
CVE-2009-4656—localwindows02 mar 2012
Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-as
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.5 - RealText Subtitle Overflow (Metasploit)
CVE-2008-5036—localwindows02 mar 2012
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RIESGO
abrir ↗
Exploit-DB
phxEventManager 2.0 Beta 5 - 'search.php' search_terms SQL Injection
CVE-2012-1124—webappsphp02 mar 2012
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB
Drupal 7.12 - Multiple Vulnerabilities
CVE-2007-6752—webappsphp02 mar 2012
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authent
23RIESGO
abrir ↗
Exploit-DB
Novell Groupwise - Address Book Remote Code Execution
CVE-2011-4189—doswindows01 mar 2012
The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial
28RIESGO
abrir ↗
Metasploit300
Ricoh DC DL-10 SR10 FTP USER Command Buffer Overflow
CVE-2012-5002—01 mar 2012
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file
50RIESGO
abrir ↗
Metasploit300
IBM Tivoli Provisioning Manager Express for Software Distribution Isig.isigCtl.1 ActiveX RunAndUploadFile() Method Overflow
CVE-2012-0198—01 mar 2012
Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provision
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dotclear 2.4.1.2 - '/admin/plugin.php?page' Cross-Site Scripting
CVE-2012-1039—webappsphp29 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netmechanica NetDecision Traffic Grapher Server - Information Disclosure
CVE-2012-1466—remotewindows29 feb 2012
The Traffic Grapher Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the source code o
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netmechanica NetDecision Dashboard Server - Information Disclosure
CVE-2012-1464—remotewindows29 feb 2012
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Netmechanica NetDecision HTTP Server - Denial of Service
CVE-2012-1465—doswindows29 feb 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir ↗
Exploit-DB
Yealink VOIP Phone - Persistent Cross-Site Scripting
CVE-2012-1417—webappshardware29 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow
23RIESGO
abrir ↗
Exploit-DB
ImgPals Photo Host 1.0 - Admin Account Disactivation
CVE-2012-4926—webappsphp29 feb 2012
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dotclear 2.4.1.2 - '/admin/comments.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-1039—webappsphp29 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNOME NetworkManager 0.x - Local Arbitrary File Access
CVE-2012-1096—locallinux29 feb 2012
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connect
23RIESGO
abrir ↗
Exploit-DB
ImgPals Photo Host 1.0 - Admin Account Disactivation
CVE-2012-4925—webappsphp29 feb 2012
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dotclear 2.4.1.2 - '/admin/blogs.php?nb' Cross-Site Scripting
CVE-2012-1039—webappsphp29 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dotclear 2.4.1.2 - '/admin/auth.php?login_data' Cross-Site Scripting
CVE-2012-1039—webappsphp29 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ASUS Net4Switch - 'ipswcom.dll' ActiveX Stack Buffer Overflow (Metasploit)
CVE-2012-4924—remotewindows29 feb 2012
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 all
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Personal Communications I-Series Access Workstation 5.9 - Profile (Metasploit)
CVE-2012-0201—remotewindows29 feb 2012
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x befo
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fork CMS 3.x - '/private/en/locale/index?name' Cross-Site Scripting
CVE-2012-1188—webappsphp28 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fork CMS 3.x - '/backend/modules/error/actions/index.php?parse()' Multiple Error Display Cross-Site Scripting Vulnerabilities
CVE-2012-1188—webappsphp28 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Fork CMS before 3.2.7 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Metasploit500
IBM Personal Communications iSeries Access WorkStation 5.9 Profile
CVE-2012-0201—28 feb 2012
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x befo
50RIESGO
abrir ↗
Exploit-DB
WebfolioCMS 1.1.4 - Cross-Site Request Forgery (Add Admin/Modify Pages)
CVE-2012-1498—webappsphp28 feb 2012
Multiple cross-site request forgery (CSRF) vulnerabilities in Webfolio CMS 1.1.4 and earlier allow remote attackers to h
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Endian Firewall 2.4 - 'openvpn_users.cgi?PATH_INFO' Cross-Site Scripting
CVE-2012-4923—remotehardware27 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OSQA's CMS - Multiple HTML Injection Vulnerabilities
CVE-2012-1782—webappsphp27 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in questions/ask in OSQA 3b allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Endian Firewall 2.4 - 'dnat.cgi?createrule' Cross-Site Scripting
CVE-2012-4923—remotehardware27 feb 2012
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Exploit-DB
Mozilla Firefox 4.0.1 - 'Array.reduceRight()' Remote Overflow
CVE-2011-2371—remotewindows27 feb 2012
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RIESGO
abrir ↗
Metasploit300
Sysax 5.53 SSH Username Buffer Overflow
CVE-2012-10060CRITICAL27 feb 2012
Sysax Multi Server < 5.55 SSH Username Buffer Overflow
63RIESGO
abrir ↗
← anteriorpágina 1196 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.