Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
CVE-2011-1425remotewindows18 oct 2011
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, a
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
CVE-2011-1774remotewindows18 oct 2011
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RIESGO
abrir
Exploit-DB
GNUBoard 4.33.02 - 'tp.php?PATH_INFO' SQL Injection
CVE-2011-4066webappsphp17 oct 2011
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari - 'file://' Arbitrary Code Execution (Metasploit)
CVE-2011-3230remoteosx17 oct 2011
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RIESGO
abrir
Exploit-DBVexDay Proof
Toshiba e-Studio (Multiple Devices) - Security Bypass
CVE-2012-1239remotemultiple17 oct 2011
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmwa
23RIESGO
abrir
Exploit-DB
Microsoft Windows - TCP/IP Stack Denial of Service (MS11-064)
CVE-2011-1965doswindows15 oct 2011
Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properl
28RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.2 - 'onlyforuser' SQL Injection
CVE-2011-4559webappsphp15 oct 2011
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
CVE-2011-4520doswindows13 oct 2011
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
CVE-2011-4519doswindows13 oct 2011
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (Metasploit) (2)
CVE-2011-2371remotewindows13 oct 2011
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - '.fon' Kernel-Mode Buffer Overrun (PoC) (MS11-077)
CVE-2011-2003doswindows13 oct 2011
Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
CVE-2011-4518doswindows13 oct 2011
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remo
28RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (1)
CVE-2011-2371remotewindows12 oct 2011
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RIESGO
abrir
Exploit-DBVexDay Proof
PcVue 10.0 SV.UIGrdCtrl.1 - 'LoadObject()'/'SaveObject()' Trusted DWORD (Metasploit)
CVE-2011-4044remotewindows12 oct 2011
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RIESGO
abrir
Exploit-DBVexDay Proof
Apache mod_proxy - Reverse Proxy Exposure
CVE-2011-3368remotemultiple11 oct 2011
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RIESGO
abrir
Exploit-DBVexDay Proof
SilverStripe CMS 2.4.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-4958webappsphp11 oct 2011
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Select Element Memory Corruption
CVE-2011-1999remotewindows11 oct 2011
Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arb
28RIESGO
abrir
Exploit-DBVexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Parsing Buffer Overflow (Metasploit)
CVE-2008-4779localwindows11 oct 2011
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir
Exploit-DBVexDay Proof
ACDSee FotoSlate - '.PLP' File 'id' Local Overflow (Metasploit)
CVE-2011-2595localwindows10 oct 2011
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RIESGO
abrir
Exploit-DBVexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
CVE-2011-4881doswindows10 oct 2011
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions,
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Forum Userbar Plugin (Userbar 2.2) - SQL Injection
CVE-2011-4569webappsphp10 oct 2011
SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
OPC Systems.NET 4.00.0048 - Denial of Service
CVE-2011-4871doswindows10 oct 2011
Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed
23RIESGO
abrir
Exploit-DBVexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
CVE-2011-4883doswindows10 oct 2011
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, w
23RIESGO
abrir
Exploit-DBVexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
CVE-2011-4880doswindows10 oct 2011
Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
CVE-2011-5277webappsphp10 oct 2011
Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.18 - 'addgroup.asp?group' Cross-Site Scripting
CVE-2011-4273remotewindows10 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.18 - 'addlimit.asp?url' Cross-Site Scripting
CVE-2011-4273remotewindows10 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
CVE-2011-4882doswindows10 oct 2011
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.18 - 'adduser.asp' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-4273remotewindows10 oct 2011
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
CVE-2011-5278webappsphp10 oct 2011
SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allow
23RIESGO
abrir
anteriorpágina 314 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.