Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit600
WordPress WP-Property PHP File Upload Vulnerability
CVE-2012-10027CRITICAL26 mar 2012
WordPress Plugin WP-Property <= 1.35.0 PHP File Upload
63RIESGO
abrir
Metasploit400
TFM MMPlayer (m3u/ppl File) Buffer Overflow
CVE-2009-256623 mar 2012
Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary cod
50RIESGO
abrir
Metasploit300
FlexNet License Server Manager lmgrd Buffer Overflow
CVE-2011-413523 mar 2012
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Man
30RIESGO
abrir
Metasploit300
Cisco Linksys PlayerPT ActiveX Control Buffer Overflow
CVE-2012-028422 mar 2012
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.o
50RIESGO
abrir
Metasploit0
FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution
CVE-2012-486920 mar 2012
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir
Metasploit300
MS12-020 Microsoft Remote Desktop Use-After-Free DoS
CVE-2012-000216 mar 2012
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RIESGO
abrir
Metasploit300
VLC MMS Stream Handling Buffer Overflow
CVE-2012-177515 mar 2012
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code
50RIESGO
abrir
Metasploit300
Sockso Music Host Server 1.5 Directory Traversal
CVE-2012-10061HIGH14 mar 2012
Sockso Music Host Server <= 1.5 Path Traversal
36RIESGO
abrir
Metasploit300
HP Data Protector Create New Folder Buffer Overflow
CVE-2012-012412 mar 2012
Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974
50RIESGO
abrir
Metasploit300
NetDecision NOCVision Server Directory Traversal
CVE-2012-146507 mar 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir
Metasploit300
IBM Tivoli Provisioning Manager Express for Software Distribution Isig.isigCtl.1 ActiveX RunAndUploadFile() Method Overflow
CVE-2012-019801 mar 2012
Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provision
50RIESGO
abrir
Metasploit300
Ricoh DC DL-10 SR10 FTP USER Command Buffer Overflow
CVE-2012-500201 mar 2012
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file
50RIESGO
abrir
Metasploit500
IBM Personal Communications iSeries Access WorkStation 5.9 Profile
CVE-2012-020128 feb 2012
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x befo
50RIESGO
abrir
Metasploit300
Sysax 5.53 SSH Username Buffer Overflow
CVE-2012-10060CRITICAL27 feb 2012
Sysax Multi Server < 5.55 SSH Username Buffer Overflow
63RIESGO
abrir
Metasploit300
NetDecision 4.5.1 HTTP Server Buffer Overflow
CVE-2012-146524 feb 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RIESGO
abrir
Metasploit300
Csound hetro File Handling Stack Buffer Overflow
CVE-2012-027023 feb 2012
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a cra
50RIESGO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x6c Buffer Overflow
CVE-2011-317522 feb 2012
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allo
50RIESGO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x4c Buffer Overflow
CVE-2011-317622 feb 2012
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allo
50RIESGO
abrir
Metasploit300
ASUS Net4Switch ipswcom.dll ActiveX Stack Buffer Overflow
CVE-2012-492417 feb 2012
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 all
50RIESGO
abrir
Metasploit300
Adobe Flash Player MP4 'cprt' Overflow
CVE-2012-0754HIGHbajo ataque15 feb 2012
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.
100RIESGO
abrir
Metasploit600
LANDesk Lenovo ThinkManagement Console Remote Command Execution
CVE-2012-119515 feb 2012
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup
50RIESGO
abrir
Metasploit600
LANDesk Lenovo ThinkManagement Console Remote Command Execution
CVE-2012-119615 feb 2012
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagemen
50RIESGO
abrir
Metasploit600
Sun Java Web Start Plugin Command Line Argument Injection
CVE-2012-050014 feb 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Up
50RIESGO
abrir
Metasploit600
Java AtomicReferenceArray Type Violation Vulnerability
CVE-2012-0507CRITICALbajo ataqueransomware14 feb 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Up
100RIESGO
abrir
Metasploit600
Horde 3.3.12 Backdoor Arbitrary PHP Code Execution
CVE-2012-020913 feb 2012
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November
60RIESGO
abrir
Metasploit300
RabidHamster R4 Log Entry sprintf() Buffer Overflow
CVE-2012-10058CRITICAL09 feb 2012
RabidHamster R4 Log Entry sprintf() Buffer Overflow
63RIESGO
abrir
Metasploit600
vBSEO proc_deutf() Remote PHP Code Injection
CVE-2012-522323 ene 2012
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allo
50RIESGO
abrir
Metasploit600
PolarBear CMS PHP File Upload Vulnerability
CVE-2013-080321 ene 2012
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RIESGO
abrir
Metasploit300
General Electric D20 Password Recovery
CVE-2012-666319 ene 2012
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
18RIESGO
abrir
Metasploit600
appRain CMF Arbitrary PHP File Upload Vulnerability
CVE-2012-115319 ene 2012
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.