Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
SWAT Samba Web Administration Tool - Cross-Site Request Forgery
CVE-2011-2522webappscgi27 jul 2011
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x befo
28RIESGO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'billable_incidents.php?sites[]' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir
Exploit-DB
Apple Safari 5.0.5 - SVG Remote Code Execution (DEP Bypass)
CVE-2011-0222remotewindows26 jul 2011
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of ser
28RIESGO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'search.php?search_string' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'tasks.php?selected[]' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'report_marketing.php?exc[]' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir
Exploit-DB
Apple Safari 5.0.6/5.1 - SVG DOM Processing (PoC)
CVE-2011-0222dososx25 jul 2011
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of ser
28RIESGO
abrir
Exploit-DBVexDay Proof
CA Arcserve D2D - GWT RPC Credential Information Disclosure (Metasploit)
CVE-2011-3011localwindows25 jul 2011
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RIESGO
abrir
Exploit-DBVexDay Proof
Tiki Wiki CMS Groupware 7.2 - 'snarf_ajax.php' Cross-Site Scripting
CVE-2011-4336webappsphp20 jul 2011
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
38RIESGO
abrir
Exploit-DB
Oracle Sun GlassFish Enterprise Server - Persistent Cross-Site Scripting
CVE-2011-2260webappsjsp20 jul 2011
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
GDI+ - 'gdiplus.dll' CreateDashedPath Integer Overflow
CVE-2011-0041doswindows18 jul 2011
Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1
28RIESGO
abrir
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'Toolbar.exe' CGI Cookie Handling Buffer Overflow (Metasploit)
CVE-2009-0920remotewindows16 jul 2011
Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow
60RIESGO
abrir
Exploit-DBVexDay Proof
Java RMI - Server Insecure Default Configuration Java Code Execution (Metasploit)
CVE-2011-3556remotemultiple15 jul 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x - '/admin/help.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-2743webappsphp13 jul 2011
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting
CVE-2011-2743webappsphp13 jul 2011
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Flowplayer 3.2.7 - 'linkUrl' Cross-Site Scripting
CVE-2011-3642webappsmultiple12 jul 2011
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) ext
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - 'nsTreeRange' Dangling Pointer (Metasploit) (1)
CVE-2011-0073remotewindows10 jul 2011
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Backup Exec 12.5 - Man In The Middle
CVE-2011-0546remotewindows09 jul 2011
Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media s
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
CVE-2011-2506webappsphp09 jul 2011
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
CVE-2011-2505webappsphp09 jul 2011
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RIESGO
abrir
Exploit-DBVexDay Proof
Blue Coat Authentication and Authorization Agent (BCAAA) 5 - Remote Buffer Overflow (Metasploit)
CVE-2011-5124remotewindows09 jul 2011
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 an
50RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin3 (pma3) - Remote Code Execution
CVE-2011-2505webappsphp08 jul 2011
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin3 (pma3) - Remote Code Execution
CVE-2011-2506webappsphp08 jul 2011
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RIESGO
abrir
Exploit-DBVexDay Proof
MicroP 0.1.1.1600 - '.mppl' Local Stack Buffer Overflow (Metasploit)
CVE-2010-5299localwindows07 jul 2011
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir
Exploit-DB
ManageEngine ServiceDesk 8.0.0.12 - Database Disclosure
CVE-2011-2755webappsjsp07 jul 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RIESGO
abrir
Exploit-DB
ManageEngine ServiceDesk 8.0.0.12 - Database Disclosure
CVE-2011-2757webappsjsp07 jul 2011
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir
Exploit-DBVexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
CVE-2011-2523remoteunix05 jul 2011
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Reader 5.1 - XFDF Buffer Overflow (SEH)
CVE-2004-0194localwindows04 jul 2011
Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to ex
28RIESGO
abrir
Exploit-DBVexDay Proof
HP OmniInet.exe Opcode 20 - Remote Buffer Overflow (Metasploit)
CVE-2011-1865remotewindows04 jul 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.3.6 - Local Buffer Overflow (ROP)
CVE-2011-1938localmultiple04 jul 2011
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might all
28RIESGO
abrir
anteriorpágina 320 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.