Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.0.3 - '.png' ReadAV Crash (PoC)
CVE-2012-5470doswindows11 oct 2012
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - Denial of Service
CVE-2012-5672doswindows11 oct 2012
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cau
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel UDEV < 1.4.1 - 'Netlink' Local Privilege Escalation (Metasploit)
CVE-2009-1185locallinux10 oct 2012
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 3.5.2.2 - 'server_sync.php' Backdoor (Metasploit)
CVE-2012-5159webappsphp10 oct 2012
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an e
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'AfdJoinLeaf' Local Privilege Escalation (MS11-080) (Metasploit)
CVE-2011-2005HIGHbajo ataquelocalwindows10 oct 2012
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly valid
98RIESGO
abrir
Exploit-DBVexDay Proof
NTR - ActiveX Control 'StopModule()' Remote Code Execution (Metasploit)
CVE-2012-0267remotewindows10 oct 2012
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir
Exploit-DBVexDay Proof
InduSoft Web Studio - Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2011-4051remotewindows10 oct 2012
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au
50RIESGO
abrir
Exploit-DBVexDay Proof
Avaya IP Office Customer Call Reporter - 'ImageUpload.ashx' Remote Command Execution (Metasploit)
CVE-2012-3811remotewindows10 oct 2012
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - execCommand Use-After-Free (MS12-063) (Metasploit)
CVE-2012-4969HIGHbajo ataqueremotewindows10 oct 2012
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenX 2.8.10 - 'plugin-index.php' Cross-Site Scripting
CVE-2012-4989webappsphp10 oct 2012
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
NTR - ActiveX Control 'Check()' Method Buffer Overflow (Metasploit)
CVE-2012-0266remotewindows10 oct 2012
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RIESGO
abrir
Exploit-DBVexDay Proof
Samba 3.4.16/3.5.14/3.6.4 - SetInformationPolicy AuditEventsInfo Heap Overflow (Metasploit)
CVE-2012-1182remotelinux10 oct 2012
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement valida
60RIESGO
abrir
Exploit-DBVexDay Proof
Webmin 1.580 - '/file/show.cgi' Remote Command Execution (Metasploit)
CVE-2012-2982remoteunix10 oct 2012
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
CVE-2006-3459remoteios09 oct 2012
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
CVE-2010-0188HIGHbajo ataqueransomwareremoteios09 oct 2012
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
CVE-2010-0188HIGHbajo ataqueransomwareremoteios09 oct 2012
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.2.x - 'uname()' System Call Local Information Disclosure
CVE-2012-0957locallinux09 oct 2012
The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive i
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
CVE-2006-3459remoteios09 oct 2012
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and othe
50RIESGO
abrir
Exploit-DBVexDay Proof
JPEGsnoop 1.5.2 - WriteAV Crash (PoC)
CVE-2012-6307doswindows04 oct 2012
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious
23RIESGO
abrir
Exploit-DBVexDay Proof
PowerTCP WebServer for - ActiveX Denial of Service
CVE-2012-3819doswindows28 sep 2012
Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Control Manager 5.5/6.0 AdHocQuery - (Authenticated) Blind SQL Injection
CVE-2012-2998webappswindows27 sep 2012
SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 b
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin MF Gig Calendar - Cross-Site Scripting
CVE-2012-4242webappsphp20 sep 2012
Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote attackers to in
38RIESGO
abrir
Exploit-DBVexDay Proof
Novell Groupwise 8.0.2 HP3 and 2012 - Integer Overflow
CVE-2012-0271doswindows17 sep 2012
Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 befo
28RIESGO
abrir
Exploit-DBVexDay Proof
CoSoSys Endpoint Protector - Predictable Password Generation
CVE-2012-2994remotehardware17 sep 2012
The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome for Android - com.android.browser.application_id Intent Extra Data Cross-Site Scripting
CVE-2012-4905remoteandroid12 sep 2012
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp - MAKI Buffer Overflow (Metasploit)
CVE-2009-1831localwindows12 sep 2012
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome for Android - Same-origin Policy Bypass Local Symlink
CVE-2012-4908remoteandroid12 sep 2012
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome for Android - Local Application Handling Cookie Theft
CVE-2012-4909remoteandroid12 sep 2012
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted applicat
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome for Android - Multiple 'file::' URL Handler Local Downloaded Content Disclosure Vulnerabilities
CVE-2012-4906remoteandroid12 sep 2012
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
libguac - Remote Buffer Overflow
CVE-2012-4415remotelinux11 sep 2012
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote a
28RIESGO
abrir
anteriorpágina 117 / 636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.