Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
CVE-2011-4882doswindows10 oct 2011
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.18 - 'adduser.asp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-4273remotewindows10 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.18 - 'addlimit.asp?url' Cross-Site Scripting
CVE-2011-4273remotewindows10 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
CVE-2011-4881doswindows10 oct 2011
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions,
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
CVE-2011-5278webappsphp10 oct 2011
SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allow
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
CVE-2011-5277webappsphp10 oct 2011
Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4
23RIESGO
abrir
Exploit-DBVexDay Proof
ScriptFTP 3.3 - LIST Remote Buffer Overflow (Metasploit) (2)
CVE-2011-3976remotewindows09 oct 2011
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Time Returns 2.0 - SQL Injection
CVE-2011-4570webappsphp08 oct 2011
SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.3.11/5.4.0RC2 - 'header()' HTTP Header Injection
CVE-2011-1398remotephp06 oct 2011
The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequenc
28RIESGO
abrir
Exploit-DBVexDay Proof
Active CMS 1.2 - 'mod' Cross-Site Scripting
CVE-2011-4564webappsphp06 oct 2011
Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Opera 10/11 - Bad Nesting with Frameset Tag Memory Corruption (Metasploit)
CVE-2011-2628remotewindows06 oct 2011
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary cod
28RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.2.1 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities (1)
CVE-2011-4670webappsphp04 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.2.1 - 'PHPrint.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-4670webappsphp04 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome < 14.0.835.163 - '.pdf' File Handling Memory Corruption
CVE-2011-2841doswindows04 oct 2011
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, w
23RIESGO
abrir
Exploit-DBVexDay Proof
Phorum 5.2.18 - '/admin/index.php' Cross-Site Scripting
CVE-2011-4561webappsphp03 oct 2011
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
Netvolution 2.5.8 - 'referer' Header SQL Injection
CVE-2011-3340webappsphp03 oct 2011
SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
Perl 5.x - Digest Module 'Digest->new()' Code Injection
CVE-2011-3597remotelinux02 oct 2011
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arb
28RIESGO
abrir
Exploit-DBVexDay Proof
ContaoCMS 2.10.1 - Cross-Site Scripting
CVE-2011-4335webappsphp02 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
CA Total Defense Suite - reGenerateReports Stored procedure SQL Injection (Metasploit)
CVE-2011-1653webappscgi02 oct 2011
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before S
60RIESGO
abrir
Exploit-DBVexDay Proof
Banana Dance CMS and Wiki - SQL Injection
CVE-2011-5168webappsphp02 oct 2011
SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
SonicWALL Viewpoint 6.0 - 'scheduleID' SQL Injection
CVE-2011-5169webappsphp02 oct 2011
SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2
23RIESGO
abrir
Exploit-DBVexDay Proof
Polipo 1.0.4.1 - POST/PUT HTTP Header Processing Denial of Service
CVE-2011-3596dosmultiple01 oct 2011
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme Black-LetterHead 1.5 - 'index.php' Cross-Site Scripting
CVE-2011-3865webappsphp30 sep 2011
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - UIPC socket heap Overflow (PoC)
CVE-2011-4062dosfreebsd30 sep 2011
Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme RedLine 1.65 - 's' Cross-Site Scripting
CVE-2011-3863webappsphp30 sep 2011
Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to injec
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - UIPC socket heap Overflow (PoC)
CVE-2011-3633dosfreebsd30 sep 2011
20RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme Morning Coffee 3.5 - 'index.php' Cross-Site Scripting
CVE-2011-3862webappsphp30 sep 2011
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme Atahualpa 3.6.7 - 's' Cross-Site Scripting
CVE-2011-3850webappsphp29 sep 2011
Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme EvoLve 1.2.5 - 's' Cross-Site Scripting
CVE-2011-3852webappsphp29 sep 2011
Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to injec
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme Pixiv Custom Theme 2.1.5 - 'cpage' Cross-Site Scripting
CVE-2011-3858webappsphp29 sep 2011
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to
23RIESGO
abrir
anteriorpágina 151 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.