Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Apple Safari file:// Arbitrary Code Execution
CVE-2011-323012 oct 2011
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RIESGO
abrir
Metasploit400
ScriptFTP LIST Remote Buffer Overflow
CVE-2011-397612 oct 2011
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RIESGO
abrir
Metasploit600
myBB 1.6.4 Backdoor Arbitrary Command Execution
CVE-2011-10018CRITICAL06 oct 2011
myBB 1.6.4 Backdoor Arbitrary Command Execution
63RIESGO
abrir
Metasploit600
Spreecommerce 0.60.1 Arbitrary Command Execution
CVE-2011-10019CRITICAL05 oct 2011
Spreecommerce < 0.60.2 Search Parameter RCE
63RIESGO
abrir
Metasploit200
PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability
CVE-2011-404405 oct 2011
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RIESGO
abrir
Metasploit600
Plone and Zope XMLTools Remote Command Execution
CVE-2011-358704 oct 2011
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RIESGO
abrir
Metasploit400
Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
CVE-2011-10015CRITICAL02 oct 2011
Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow
43RIESGO
abrir
Metasploit600
Apache Struts ParametersInterceptor Remote Code Execution
CVE-2011-392301 oct 2011
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RIESGO
abrir
Metasploit500
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
CVE-2011-10032CRITICAL22 sep 2011
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
63RIESGO
abrir
Metasploit600
Snortreport nmap.php/nbtscan.php Remote Command Execution
CVE-2011-10017CRITICAL19 sep 2011
Snort Report nmap.php/nbtscan.php RCE
63RIESGO
abrir
Metasploit300
GTA SA-MP server.cfg Buffer Overflow
CVE-2011-10014HIGH18 sep 2011
GTA SA-MP server.cfg Buffer Overflow
36RIESGO
abrir
Metasploit600
Measuresoft ScadaPro Remote Command Execution
CVE-2011-349716 sep 2011
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the
50RIESGO
abrir
Metasploit400
DaqFactory HMI NETB Request Overflow
CVE-2011-349213 sep 2011
Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial
60RIESGO
abrir
Metasploit300
Beckhoff TwinCAT SCADA PLC 2.11.0.2004 DoS
CVE-2011-348613 sep 2011
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to U
50RIESGO
abrir
Metasploit400
ACDSee FotoSlate PLP File id Parameter Overflow
CVE-2011-259512 sep 2011
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RIESGO
abrir
Metasploit500
CyberLink Power2Go name Attribute (p2g) Stack Buffer Overflow Exploit
CVE-2011-517112 sep 2011
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to e
50RIESGO
abrir
Metasploit400
ScadaTEC ScadaPhone Stack Buffer Overflow
CVE-2011-453512 sep 2011
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RIESGO
abrir
Metasploit300
Procyon Core Server HMI Coreservice.exe Stack Buffer Overflow
CVE-2011-332208 sep 2011
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows
50RIESGO
abrir
Metasploit200
CTEK SkyRouter 4200 and 4300 Command Execution
CVE-2011-501008 sep 2011
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via sh
50RIESGO
abrir
Metasploit300
eSignal and eSignal Pro File Parsing Buffer Overflow in QUO
CVE-2011-349406 sep 2011
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
50RIESGO
abrir
Metasploit300
rsyslog Long Tag Off-By-Two DoS
CVE-2011-320001 sep 2011
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before
23RIESGO
abrir
Metasploit500
Free MP3 CD Ripper 1.1 WAV File Stack Buffer Overflow
CVE-2011-516527 ago 2011
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Metasploit300
Apache Range Header DoS (Apache Killer)
CVE-2011-319219 ago 2011
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
Metasploit500
HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution
CVE-2011-240416 ago 2011
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
60RIESGO
abrir
Metasploit200
RealNetworks Realplayer QCP Parsing Heap Overflow
CVE-2011-295016 ago 2011
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and
43RIESGO
abrir
Metasploit600
ktsuss suid Privilege Escalation
CVE-2011-292113 ago 2011
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RIESGO
abrir
Metasploit300
TeeChart Professional ActiveX Control Trusted Integer Dereference
CVE-2011-403411 ago 2011
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier,
23RIESGO
abrir
Metasploit300
Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
CVE-2011-214009 ago 2011
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adob
60RIESGO
abrir
Metasploit300
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
CVE-2011-010509 ago 2011
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RIESGO
abrir
Metasploit400
Apple QuickTime PICT PnSize Buffer Overflow
CVE-2011-025708 ago 2011
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.