Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
Exploit-DB✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (Metasploit)
CVE-2009-1028—localwindows25 abr 2011
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RIESGO
abrir ↗
Exploit-DB
PHP 'phar' Extension 1.1.1 - Heap Overflow
CVE-2012-2386—dosmultiple22 abr 2011
Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before
35RIESGO
abrir ↗
Exploit-DB
SocialCMS 1.0.2 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2012-1416—webappsphp20 abr 2011
Multiple cross-site request forgery (CSRF) vulnerabilities in SocialCMS 1.0.2 allow remote attackers to hijack the authe
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/JASMafletMafBrowserClose.mafService?jdemafjasLinkTarget' Cross-Site Scripting
CVE-2011-0836—remotemultiple19 abr 2011
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/MafletClose.mafService?RENDER_MAFLET' Cross-Site Scripting
CVE-2011-0836—remotemultiple19 abr 2011
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_Menu.mafService?e1.namespace' Cross-Site Scripting
CVE-2011-0836—remotemultiple19 abr 2011
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24
23RIESGO
abrir ↗
Metasploit600
Spreecommerce Arbitrary Command Execution
CVE-2011-10026CRITICAL19 abr 2011
Spreecommerce < 0.50.x API RCE
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark 1.4.4 - 'packet-dect.c' Local Stack Buffer Overflow (Metasploit) (1)
CVE-2011-1591—localwindows19 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_OCL.mafService?e1.namespace' Cross-Site Scripting
CVE-2011-0836—remotemultiple19 abr 2011
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player < 10.1.53.64 - Action Script Type Confusion (ASLR + DEP Bypass)
CVE-2010-3654—remotewindows19 abr 2011
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 o
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark 1.4.4 - 'packet-dect.c' Remote Stack Buffer Overflow (Metasploit) (2)
CVE-2011-1591—remotewindows19 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Tivoli Directory Server SASL - Bind Request Remote Code Execution
CVE-2011-1206—doswindows19 abr 2011
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu.maf?jdeowpBackButtonProtect' Cross-Site Scripting
CVE-2011-0836—remotemultiple19 abr 2011
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireshark 1.4.1 < 1.4.4 - Local Overflow (SEH)
CVE-2011-1591—localwindows18 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir ↗
Metasploit400
Wireshark packet-dect.c Stack Buffer Overflow
CVE-2011-1591—18 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir ↗
Metasploit400
Wireshark packet-dect.c Stack Buffer Overflow (local)
CVE-2011-1591—18 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir ↗
Exploit-DB
FiSH-irssi 0.99 - Evil ircd Buffer Overflow
CVE-2007-1397—remotelinux17 abr 2011
Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote a
23RIESGO
abrir ↗
Exploit-DB
Microsoft Word 2003 - Record Parsing Buffer Overflow (MS09-027) (Metasploit)
CVE-2009-0565—localwindows16 abr 2011
Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 200
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe Flash Player 10.2.153.1 - SWF Memory Corruption (Metasploit)
CVE-2011-0611HIGHbajo ataqueremotewindows16 abr 2011
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
EC Software Help & Manual 5.5.1 Build 1296 - 'ijl15.dll' DLL Loading Arbitrary Code Execution
CVE-2011-5155—remotewindows14 abr 2011
Untrusted search path vulnerability in Help & Manual 5.5.1 Build 1296 allows local users to gain privileges via a Trojan
23RIESGO
abrir ↗
Metasploit600
CA Total Defense Suite reGenerateReports Stored Procedure SQL Injection
CVE-2011-1653—13 abr 2011
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before S
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Excel - Remote Buffer Overflow
CVE-2011-0104—remotewindows12 abr 2011
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow re
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Security Agent Management Console - 'st_upload' Remote Code Execution
CVE-2011-0364—remotewindows12 abr 2011
The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers
28RIESGO
abrir ↗
Metasploit300
Microsoft Windows DNSAPI.dll LLMNR Buffer Underrun DoS
CVE-2011-0657CRITICAL12 abr 2011
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Wi
55RIESGO
abrir ↗
Metasploit600
Log1 CMS writeInfo() PHP Code Injection
CVE-2011-4825—11 abr 2011
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗
Metasploit400
VeryTools Video Spirit Pro
CVE-2011-0500—11 abr 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RIESGO
abrir ↗
Metasploit400
VeryTools Video Spirit Pro
CVE-2011-0499—11 abr 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RIESGO
abrir ↗
Metasploit300
Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability
CVE-2011-0611HIGHbajo ataque11 abr 2011
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.70 - '.visprj' Local Buffer Overflow (Metasploit)
CVE-2011-0499—localwindows11 abr 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.70 - '.visprj' Local Buffer Overflow (Metasploit)
CVE-2011-0500—localwindows11 abr 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RIESGO
abrir ↗
← anteriorpágina 1232 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.