Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.814exploits catalogados
32.125CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Subtitle Processor 7.7.1 .M3U SEH Unicode Buffer Overflow
CVE-2011-10025HIGH26 abr 2011
Subtitle Processor 7.7.1 .m3u SEH Unicode Buffer Overflow
36RIESGO
abrir
Metasploit600
Spreecommerce Arbitrary Command Execution
CVE-2011-10026CRITICAL19 abr 2011
Spreecommerce < 0.50.x API RCE
63RIESGO
abrir
Metasploit400
Wireshark packet-dect.c Stack Buffer Overflow (local)
CVE-2011-159118 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir
Metasploit400
Wireshark packet-dect.c Stack Buffer Overflow
CVE-2011-159118 abr 2011
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir
Metasploit600
CA Total Defense Suite reGenerateReports Stored Procedure SQL Injection
CVE-2011-165313 abr 2011
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before S
60RIESGO
abrir
Metasploit300
Microsoft Windows DNSAPI.dll LLMNR Buffer Underrun DoS
CVE-2011-0657CRITICAL12 abr 2011
DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Wi
55RIESGO
abrir
Metasploit400
VeryTools Video Spirit Pro
CVE-2011-049911 abr 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RIESGO
abrir
Metasploit400
VeryTools Video Spirit Pro
CVE-2011-050011 abr 2011
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RIESGO
abrir
Metasploit300
Adobe Flash Player 10.2.153.1 SWF Memory Corruption Vulnerability
CVE-2011-0611HIGHbajo ataque11 abr 2011
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RIESGO
abrir
Metasploit600
Log1 CMS writeInfo() PHP Code Injection
CVE-2011-482511 abr 2011
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir
Metasploit300
S40 0.4.2 CMS Directory Traversal Vulnerability
CVE-2011-10009HIGH07 abr 2011
S40 CMS 0.4.2 Path Traversal
36RIESGO
abrir
Metasploit200
VideoLAN VLC ModPlug ReadS3M Stack Buffer Overflow
CVE-2011-157407 abr 2011
Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers t
50RIESGO
abrir
Metasploit400
Blue Coat Authentication and Authorization Agent (BCAAA) 5 Buffer Overflow
CVE-2011-512404 abr 2011
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 an
50RIESGO
abrir
Metasploit300
Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
CVE-2011-10028HIGH03 abr 2011
RealNetworks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution
36RIESGO
abrir
Metasploit500
Linux PolicyKit Race Condition Privilege Escalation
CVE-2011-148501 abr 2011
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RIESGO
abrir
Metasploit400
7-Technologies IGSS IGSSdataServer.exe Stack Buffer Overflow
CVE-2011-156724 mar 2011
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Grap
50RIESGO
abrir
Metasploit600
7-Technologies IGSS 9 Data Server/Collector Packet Handling Vulnerabilities
CVE-2011-156624 mar 2011
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RIESGO
abrir
Metasploit600
7-Technologies IGSS 9 Data Server/Collector Packet Handling Vulnerabilities
CVE-2011-156524 mar 2011
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RIESGO
abrir
Metasploit300
7-Technologies IGSS 9 IGSSdataServer .RMS Rename Buffer Overflow
CVE-2011-156724 mar 2011
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Grap
50RIESGO
abrir
Metasploit400
VLC AMV Dangling Pointer Vulnerability
CVE-2010-327523 mar 2011
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a
60RIESGO
abrir
Metasploit600
Interactive Graphical SCADA System Remote Command Injection
CVE-2011-156621 mar 2011
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RIESGO
abrir
Metasploit500
RealWin SCADA Server DATAC Login Buffer Overflow
CVE-2011-156321 mar 2011
Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier
60RIESGO
abrir
Metasploit500
DATAC RealWin SCADA Server 2 On_FC_CONNECT_FCS_a_FILE Buffer Overflow
CVE-2011-156321 mar 2011
Multiple stack-based buffer overflows in the HMI application in DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and earlier
60RIESGO
abrir
Metasploit200
MPlayer Lite M3U Buffer Overflow
CVE-2011-10008HIGH19 mar 2011
MPlayer Lite r33064 M3U Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit400
Adobe Flash Player AVM Bytecode Verification Vulnerability
CVE-2011-0609HIGHbajo ataque15 mar 2011
Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.1
98RIESGO
abrir
Metasploit300
Majordomo2 _list_file_get() Directory Traversal
CVE-2011-004908 mar 2011
Directory traversal vulnerability in the _list_file_get function in lib/Majordomo.pm in Majordomo 2 before 20110131 allo
60RIESGO
abrir
Metasploit300
Majordomo2 _list_file_get() Directory Traversal
CVE-2011-006308 mar 2011
The _list_file_get function in lib/Majordomo.pm in Majordomo 2 20110203 and earlier allows remote attackers to conduct d
60RIESGO
abrir
Metasploit300
Foxit PDF Reader 4.2 Javascript File Write
CVE-2011-10030HIGH05 mar 2011
Foxit PDF Reader < 4.3.1.0218 JavaScript File Write
36RIESGO
abrir
Metasploit600
LotusCMS 3.0 eval() Remote Command Execution
CVE-2011-051803 mar 2011
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir
Metasploit300
Wireshark CLDAP Dissector DOS
CVE-2011-114001 mar 2011
Multiple stack consumption vulnerabilities in the dissect_ms_compressed_string and dissect_mscldap_string functions in W
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.