Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Microsoft Windows - TCP/IP Stack Reference Counter Integer Overflow (MS11-083)
CVE-2011-2013CRITICALdoswindows08 nov 2011
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, a
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Hyperion Strategic Finance 12.x - Tidestone Formula One WorkBook OLE Control TTF16.ocx Remote Heap Overflow
CVE-2011-5167remotewindows07 nov 2011
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Buil
23RIESGO
abrir
Exploit-DBVexDay Proof
WHMCompleteSolution 3.x/4.x - Multiple Vulnerabilities
CVE-2011-4810webappsphp07 nov 2011
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RIESGO
abrir
Exploit-DBVexDay Proof
OrderSys 1.6.4 - SQL Injection
CVE-2011-5183webappsphp07 nov 2011
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DB
Oracle - xdb.xdb_pitrig_pkg.PITRIG_DROPMETADATA procedure
CVE-2007-4517remotewindows07 nov 2011
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated use
23RIESGO
abrir
Exploit-DB
KnFTP 1.0 - Remote Buffer Overflow (DEP Bypass) (Metasploit)
CVE-2011-5166remotewindows07 nov 2011
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPMyFAQ 2.7.0 - 'ajax_create_folder.php' Remote Code Execution
CVE-2011-4825webappsphp05 nov 2011
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir
Exploit-DBVexDay Proof
ZenPhoto 1.4.1.4 - 'ajax_create_folder.php' Remote Code Execution
CVE-2011-4825webappsphp05 nov 2011
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel 2007 - '.xlb' Local Buffer Overflow (MS11-021) (Metasploit)
CVE-2011-0105localwindows05 nov 2011
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RIESGO
abrir
Exploit-DBVexDay Proof
aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
CVE-2011-4825webappsphp05 nov 2011
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir
Exploit-DBVexDay Proof
Ajax File and Image Manager 1.0 Final - Remote Code Execution
CVE-2011-4825webappsphp04 nov 2011
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir
Exploit-DB
WHMCompleteSolution (WHMCS) 3.x - 'clientarea.php' Local File Disclosure
CVE-2011-4813webappsphp04 nov 2011
Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read
23RIESGO
abrir
Exploit-DBVexDay Proof
DreamBox DM800 - 'file' Local File Disclosure
CVE-2011-4716webappshardware04 nov 2011
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RIESGO
abrir
Exploit-DBVexDay Proof
Centreon 2.3.1 - 'command_name' Remote Command Execution
CVE-2011-4431webappsphp04 nov 2011
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to exe
23RIESGO
abrir
Exploit-DB
DreamBox DM800 1.5rc1 - File Disclosure
CVE-2011-4716remotehardware04 nov 2011
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RIESGO
abrir
Exploit-DBVexDay Proof
Mini-stream Ripper 3.0.1.1 - Local Buffer Overflow (Metasploit) (3)
CVE-2009-5109localwindows04 nov 2011
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e
50RIESGO
abrir
Exploit-DBVexDay Proof
Libc - 'regcomp()' Stack Exhaustion Denial of Service
CVE-2011-3336dosmultiple04 nov 2011
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android 2.3.5 - PowerVR SGX Driver Information Disclosure
CVE-2011-1350remoteandroid03 nov 2011
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel
23RIESGO
abrir
Exploit-DBVexDay Proof
Web File Browser 0.4b14 - File Download
CVE-2011-4831webappsphp03 nov 2011
Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to
23RIESGO
abrir
Exploit-DBVexDay Proof
Jara 1.6 - Multiple Vulnerabilities
CVE-2011-4095webappsphp03 nov 2011
Jara 1.6 has an XSS vulnerability
23RIESGO
abrir
Exploit-DBVexDay Proof
S9Y Serendipity 1.5.5 - 'serendipity[filter][bp.ALT]' Cross-Site Scripting
CVE-2011-4090webappsphp03 nov 2011
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
23RIESGO
abrir
Exploit-DB
SetSeed CMS 5.8.20 - 'loggedInUser' SQL Injection
CVE-2011-5116webappsphp02 nov 2011
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute
23RIESGO
abrir
Exploit-DB
Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow
CVE-2011-3607doslinux02 nov 2011
Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x th
23RIESGO
abrir
Exploit-DBVexDay Proof
BST (BestShopPro) - 'nowosci.php' Multiple Vulnerabilities
CVE-2011-4811webappsphp02 nov 2011
SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Exploit-DB
CaupoShop Pro (2.x < 3.70) Classic 3.01 - Local File Inclusion
CVE-2011-4832webappsphp02 nov 2011
Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allow
23RIESGO
abrir
Exploit-DB
Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow
CVE-2011-4415doslinux02 nov 2011
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when t
23RIESGO
abrir
Exploit-DBVexDay Proof
BST (BestShopPro) - 'nowosci.php' Multiple Vulnerabilities
CVE-2011-4812webappsphp02 nov 2011
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DBVexDay Proof
Symphony 2.2.3 - '/symphony/publish/comments?filter' SQL Injection
CVE-2011-4341webappsphp01 nov 2011
Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other
23RIESGO
abrir
Exploit-DBVexDay Proof
Symphony 2.2.3 - '/symphony/publish/images?filter' Cross-Site Scripting
CVE-2011-4340webappsphp01 nov 2011
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow
23RIESGO
abrir
Exploit-DB
ZTE ZXDSL 831IIV7.5.0a_Z29_OV - Multiple Vulnerabilities
CVE-2012-4746webappshardware01 nov 2011
Cross-site request forgery (CSRF) vulnerability in accessaccount.cgi in ZTE ZXDSL 831IIV7.5.0a_Z29_OV allows remote atta
23RIESGO
abrir
anteriorpágina 312 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.