Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
81.689 exploits
Exploit-DB✓ VexDay Proof
Novell Netware - NWFTPD.NLM DELE Remote Code Execution
CVE-2010-4228—dosnetware21 mar 2011
Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated
28RIESGO
abrir ↗
Metasploit600
Interactive Graphical SCADA System Remote Command Injection
CVE-2011-1566—21 mar 2011
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RIESGO
abrir ↗
Metasploit500
DATAC RealWin SCADA Server 2 On_FC_CONNECT_FCS_a_FILE Buffer Overflow
CVE-2011-1563—21 mar 2011
Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier
60RIESGO
abrir ↗
Exploit-DB
RealPlayer 14.0.1.633 - Heap Overflow
CVE-2011-1525—doswindows21 mar 2011
Heap-based buffer overflow in rvrender.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.2, and R
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.6.x - HFS Subsystem Information Disclosure
CVE-2011-0180—localosx21 mar 2011
Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) H
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Douran 3.9.7.8 - File Download/Source Code Disclosure
CVE-2011-1569—webappsasp20 mar 2011
download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web ro
23RIESGO
abrir ↗
Metasploit200
MPlayer Lite M3U Buffer Overflow
CVE-2011-10008HIGH19 mar 2011
MPlayer Lite r33064 M3U Stack-Based Buffer Overflow
36RIESGO
abrir ↗
Exploit-DB
PHP 5.3.5 libzip 0.9.3 - _zip_name_locate Null Pointer Dereference
CVE-2011-0421—doslinux18 mar 2011
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a Z
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer - CDDA URI Initialization (Metasploit)
CVE-2010-3747—remotewindows17 mar 2011
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterpr
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe ColdFusion - Directory Traversal (Metasploit)
CVE-2010-2861CRITICALbajo ataqueransomwareremotemultiple16 mar 2011
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RIESGO
abrir ↗
Exploit-DB
WikiWig 5.01 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-5267—webappsphp16 mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java Applet2ClassLoader - Remote Code Execution (Metasploit)
CVE-2010-4452—remotemultiple16 mar 2011
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP OpenView Performance Insight Server - Backdoor Account Code Execution (Metasploit)
CVE-2011-0276—remotewindows15 mar 2011
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SugarCRM 6.1.1 - Information Disclosure
CVE-2011-0745—webappsphp15 mar 2011
SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain dupl
23RIESGO
abrir ↗
Metasploit400
Adobe Flash Player AVM Bytecode Verification Vulnerability
CVE-2011-0609HIGHbajo ataque15 mar 2011
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.1
98RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Android 2.0/2.1/2.1.1 - WebKit Use-After-Free
CVE-2010-1119—remoteandroid14 mar 2011
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari befo
28RIESGO
abrir ↗
Exploit-DB
Linux Kenel 2.6.37-rc1 - serial_core TIOCGICOUNT Leak
CVE-2010-4077—doslinux14 mar 2011
The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.3.6 - 'shmop_read()' Integer Overflow Denial of Service
CVE-2011-1092—doslinux12 mar 2011
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of servic
28RIESGO
abrir ↗
Exploit-DB
Oracle WebLogic - POST Session Fixation
CVE-2010-4437—webappsmultiple11 mar 2011
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 1
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP < 5.3.6 'Zip' Extension - 'zip_fread()' Denial of Service
CVE-2011-1471—dosphp10 mar 2011
Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.3.x 'Zip' Extension - 'stream_get_contents()' Denial of Service
CVE-2011-1470—dosphp10 mar 2011
The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 5.3.x 'Intl' Extension - 'NumberFormatter::setSymbol()' Denial of Service
CVE-2011-1467—dosphp10 mar 2011
Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PH
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve for Laptops & Desktops LGServer - 'rxsSetDataGrowthScheduleAndFilter' Remote Buffer Overflow (Metasploit)
CVE-2007-3216—remotewindows10 mar 2011
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops a
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xinha 0.96 - 'spell-check-savedicts.php' Multiple HTML Injection Vulnerabilities
CVE-2011-5267—webappsphp10 mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as
23RIESGO
abrir ↗
Exploit-DB
FreeBSD 6.4 - Netgraph Privilege Escalation
CVE-2008-5736—localbsd10 mar 2011
Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p
23RIESGO
abrir ↗
Exploit-DB
Linux Kernel < 2.6.37-rc2 - 'TCP_MAXSEG' Kernel Panic (Denial of Service) (2)
CVE-2010-4165—doslinux10 mar 2011
The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MA
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SmarterMail 7.3/7.4 - Multiple Vulnerabilities
CVE-2010-3486—webappsasp10 mar 2011
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WebKit 1.2.x - Local Webpage Cross Domain Information Disclosure
CVE-2011-0167—remotewindows09 mar 2011
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Polic
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP < 5.3.6 'OpenSSL' Extension - 'openssl_encrypt' Plaintext Data Memory Leak Denial of Service
CVE-2011-1468—dosphp08 mar 2011
Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of ser
28RIESGO
abrir ↗
Metasploit300
Majordomo2 _list_file_get() Directory Traversal
CVE-2011-0049—08 mar 2011
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RIESGO
abrir ↗
← anteriorpágina 1235 / 2723siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.