Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
81.524 exploits
Exploit-DB✓ VexDay Proof
OSClass 2.3.3 - 'index.php?getParam()' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-0974—webappsphp25 ene 2012
Multiple cross-site scripting (XSS) vulnerabilities in the getParam function in oc-includes/osclass/core/Params.php in O
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vBadvanced CMPS 3.2.2 - 'vba_cmps_include_bottom.php' Remote File Inclusion
CVE-2012-5224—webappsphp25 ene 2012
PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OSClass 2.3.3 - 'index.php?sCategory' SQL Injection
CVE-2012-0973—webappsphp25 ene 2012
Multiple SQL injection vulnerabilities in OSClass before 2.3.5 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2012-0782—webappsphp25 ene 2012
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2012-0937—webappsphp25 ene 2012
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQ
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2011-4898—webappsphp25 ene 2012
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error message
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Core 3.3.1 - Multiple Vulnerabilities
CVE-2011-4899—webappsphp25 ene 2012
wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not ensure that the specifie
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DClassifieds 0.1 final - Cross-Site Request Forgery
CVE-2012-0990—webappsphp25 ene 2012
Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin YouSayToo auto-publishing 1.0 - 'submit' Cross-Site Scripting
CVE-2012-0901—webappsphp24 ene 2012
Cross-site scripting (XSS) vulnerability in yousaytoo.php in YouSayToo auto-publishing plugin 1.0 for WordPress allows r
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
stoneware webnetwork6 - Multiple Vulnerabilities
CVE-2012-0286—webappsjsp24 ene 2012
Cross-site request forgery (CSRF) vulnerability in Stoneware webNetwork before 6.0.8.0 allows remote attackers to hijack
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
stoneware webnetwork6 - Multiple Vulnerabilities
CVE-2012-0285—webappsjsp24 ene 2012
Multiple cross-site scripting (XSS) vulnerabilities in Stoneware webNetwork before 6.0.8.0 allow remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB
WordPress Plugin Kish Guest Posting 1.0 - Arbitrary File Upload
CVE-2012-5318—webappsphp23 ene 2012
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin 1.2 for WordP
23RIESGO
abrir ↗
Exploit-DB
WordPress Plugin Kish Guest Posting 1.0 - Arbitrary File Upload
CVE-2012-1125—webappsphp23 ene 2012
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.39 < 3.2.2 (Gentoo / Ubuntu x86/x64) - 'Mempodipper' Local Privilege Escalation (1)
CVE-2012-0056—locallinux23 ene 2012
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RIESGO
abrir ↗
Metasploit600
vBSEO proc_deutf() Remote PHP Code Injection
CVE-2012-5223—23 ene 2012
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allo
50RIESGO
abrir ↗
Exploit-DB
WordPress Plugin AllWebMenus < 1.1.9 Menu Plugin - Arbitrary File Upload
CVE-2012-1010—webappsphp22 ene 2012
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RIESGO
abrir ↗
Exploit-DB
MiniCMS 1.0/2.0 - PHP Code Injection
CVE-2012-5231—webappsphp22 ene 2012
miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variabl
23RIESGO
abrir ↗
Exploit-DB
WordPress Plugin AllWebMenus < 1.1.9 Menu Plugin - Arbitrary File Upload
CVE-2012-1011—webappsphp22 ene 2012
actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_kp - 'Controller' Local File Inclusion
CVE-2011-4804—webappsphp21 ene 2012
Directory traversal vulnerability in the obSuggest (com_obsuggest) component before 1.8 for Joomla! allows remote attack
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP iReport 1.0 - Remote Html Code Injection
CVE-2012-5315—webappsphp21 ene 2012
Multiple cross-site scripting (XSS) vulnerabilities in php ireport 1.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Exploit-DB
iSupport 1.x - Cross-Site Request Forgery / HTML Code Injection (Add Admin)
CVE-2012-5326—webappsphp21 ene 2012
Cross-site request forgery (CSRF) vulnerability in admin/function.php in IDevSpot iSupport 1.x allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Lead Capture - 'login.php' Script Cross-Site Scripting
CVE-2012-0932—webappsphp21 ene 2012
Cross-site scripting (XSS) vulnerability in admin/login.php in Lead Capture Page System allows remote attackers to injec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tribiq CMS - 'index.php' SQL Injection
CVE-2012-5312—webappsphp21 ene 2012
SQL injection vulnerability in Tribiq CMS allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir ↗
Metasploit600
PolarBear CMS PHP File Upload Vulnerability
CVE-2013-0803—21 ene 2012
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RIESGO
abrir ↗
Exploit-DB
ARYADAD - Multiple Vulnerabilities
CVE-2012-0935—webappsasp21 ene 2012
SQL injection vulnerability in Default.aspx in Aryadad CMS allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component Vik Real Estate 1.0 - Multiple SQL Injections
CVE-2011-4823—webappsphp21 ene 2012
Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Acidcat ASP CMS 3.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-0933—webappsasp21 ene 2012
Multiple cross-site scripting (XSS) vulnerabilities in Acidcat CMS 3.5.1, 3.5.2, 3.5.6, and possibly earlier allow remot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Snitz Forums 2000 - 'TOPIC_ID' SQL Injection
CVE-2012-5313—webappsasp20 ene 2012
SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ICTimeAttendance - Authentication Bypass
CVE-2012-0913—webappsasp20 ene 2012
SQL injection vulnerability in checklogin.aspx in ICloudCenter ICTimeAttendance 1.0 allows remote attackers to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager - 'ov.dll' _OVBuildPath Buffer Overflow (Metasploit)
CVE-2011-3167—remotewindows20 ene 2012
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute
50RIESGO
abrir ↗
← anteriorpágina 1203 / 2718siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.