Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
BisonWare BisonFTP Server Buffer Overflow
CVE-1999-151007 ago 2011
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RIESGO
abrir
Metasploit600
Sun/Oracle GlassFish Server Authenticated Code Execution
CVE-2011-080704 ago 2011
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RIESGO
abrir
Metasploit600
CA Arcserve D2D GWT RPC Credential Information Disclosure
CVE-2011-301125 jul 2011
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RIESGO
abrir
Metasploit600
Apple Safari Webkit libxslt Arbitrary File Creation
CVE-2011-177420 jul 2011
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RIESGO
abrir
Metasploit600
Wireshark console.lua Pre-Loading Script Execution
CVE-2011-336018 jul 2011
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RIESGO
abrir
Metasploit300
Citrix Gateway ActiveX Control Stack Based Buffer Overflow Vulnerability
CVE-2011-288214 jul 2011
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RIESGO
abrir
Metasploit600
LifeSize Room Command Injection
CVE-2011-276313 jul 2011
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitra
50RIESGO
abrir
Metasploit600
WeBid converter.php Remote PHP Code Injection
CVE-2011-10011CRITICAL05 jul 2011
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RIESGO
abrir
Metasploit600
VSFTPD 2.3.4 Backdoor Command Execution
CVE-2011-252303 jul 2011
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Metasploit300
Kaillera 0.86 Server Denial of Service
CVE-2011-10020HIGH02 jul 2011
Kaillera 0.86 Server DoS via Malformed UDP Packet
36RIESGO
abrir
Metasploit400
HP OmniInet.exe Opcode 20 Buffer Overflow
CVE-2011-186529 jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir
Metasploit500
HP OmniInet.exe Opcode 27 Buffer Overflow
CVE-2011-186529 jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir
Metasploit300
Mozilla Firefox Array.reduceRight() Integer Overflow
CVE-2011-237121 jun 2011
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RIESGO
abrir
Metasploit300
MS11-050 IE mshtml!CObjectElement Use After Free
CVE-2011-126016 jun 2011
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute
50RIESGO
abrir
Metasploit600
Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute
CVE-2011-203901 jun 2011
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Win
50RIESGO
abrir
Metasploit400
IBM Tivoli Endpoint Manager POST Query Buffer Overflow
CVE-2011-122031 may 2011
Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3
50RIESGO
abrir
Metasploit300
Sybase Easerver 6.3 Directory Traversal
CVE-2011-247425 may 2011
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers
30RIESGO
abrir
Metasploit300
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
CVE-2011-121324 may 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RIESGO
abrir
Metasploit400
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
CVE-2011-121324 may 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RIESGO
abrir
Metasploit500
VisiWave VWR File Parsing Vulnerability
CVE-2011-238620 may 2011
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to
50RIESGO
abrir
Metasploit300
MPlayer SAMI Subtitle File Buffer Overflow
CVE-2011-362519 may 2011
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RIESGO
abrir
Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free Vulnerability
CVE-2011-006510 may 2011
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RIESGO
abrir
Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free
CVE-2011-006510 may 2011
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RIESGO
abrir
Metasploit400
ICONICS WebHMI ActiveX Buffer Overflow
CVE-2011-208905 may 2011
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0
50RIESGO
abrir
Metasploit300
SPlayer 3.7 Content-Type Buffer Overflow
CVE-2011-10022HIGH04 may 2011
SPlayer 3.7 Content-Type Header Buffer Overflow
36RIESGO
abrir
Metasploit300
Tom Sawyer Software GET Extension Factory Remote Code Execution
CVE-2011-221703 may 2011
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.2
50RIESGO
abrir
Metasploit400
MJM QuickPlayer 1.00 Beta 60a / QuickPlayer 2010 .s3m Stack Buffer Overflow
CVE-2011-10023HIGH30 abr 2011
MJM QuickPlayer <= 2010 .s3m Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit400
MJM Core Player 2011 .s3m Stack Buffer Overflow
CVE-2011-10024HIGH30 abr 2011
MJM Core Player 2011 .s3m File Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit300
NetOp Remote Control Client 9.5 Buffer Overflow
CVE-2011-10012HIGH28 abr 2011
NetOp Remote Control Client 9.5 .dws File Buffer Overflow
36RIESGO
abrir
Metasploit400
Magix Musik Maker 16 .mmm Stack Buffer Overflow
CVE-2011-10021HIGH26 abr 2011
Magix Musik Maker <= v16 .mmm Stack-Based Buffer Overflow
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.