Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Solar FTP Server Malformed USER Denial of Service
CVE-2011-10029HIGH22 feb 2011
Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
36RIESGO
abrir
Metasploit600
Sun Java Applet2ClassLoader Remote Code Execution
CVE-2010-445215 feb 2011
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RIESGO
abrir
Metasploit300
xRadio 0.95b Buffer Overflow
CVE-2008-278908 feb 2011
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RIESGO
abrir
Metasploit600
HP Data Protector 6 EXEC_CMD Remote Code Execution
CVE-2011-092307 feb 2011
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RIESGO
abrir
Metasploit300
HP Data Protector 6.1 EXEC_CMD Command Execution
CVE-2011-092307 feb 2011
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RIESGO
abrir
Metasploit500
EMC Replication Manager Command Execution
CVE-2011-064707 feb 2011
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x
50RIESGO
abrir
Metasploit300
VSFTPD 2.3.2 and Earlier STAT Denial of Service
CVE-2011-076203 feb 2011
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RIESGO
abrir
Metasploit600
QuickShare File Server 1.2.1 Directory Traversal Vulnerability
CVE-2011-10010CRITICAL03 feb 2011
QuickShare File Server 1.2.1 Path Traversal RCE
63RIESGO
abrir
Metasploit300
Mozilla Firefox "nsTreeRange" Dangling Pointer Vulnerability
CVE-2011-007302 feb 2011
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RIESGO
abrir
Metasploit300
AOL Desktop 9.6 RTX Buffer Overflow
CVE-2011-10027HIGH31 ene 2011
AOL Desktop 9.6 RTX Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit400
VideoLAN VLC MKV Memory Corruption
CVE-2011-053131 ene 2011
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to
50RIESGO
abrir
Metasploit600
HP OpenView Performance Insight Server Backdoor Account Code Execution
CVE-2011-027631 ene 2011
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RIESGO
abrir
Metasploit400
Real Networks Netzip Classic 7.5.1 86 File Parsing Buffer Overflow Vulnerability
CVE-2011-10016CRITICAL30 ene 2011
Real Networks Netzip Classic 7.5.1.86 File Parsing Buffer Overflow
43RIESGO
abrir
Metasploit200
GoldenFTP PASS Stack Buffer Overflow
CVE-2006-657623 ene 2011
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RIESGO
abrir
Metasploit600
Oracle Database Client System Analyzer Arbitrary File Upload
CVE-2010-360018 ene 2011
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RIESGO
abrir
Metasploit500
Sielco Sistemi Winlog Buffer Overflow
CVE-2011-051713 ene 2011
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RIESGO
abrir
Metasploit300
HP OpenView NNM nnmRptConfig nameParams Buffer Overflow
CVE-2011-026610 ene 2011
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers t
60RIESGO
abrir
Metasploit300
HP OpenView NNM nnmRptConfig.exe schdParams Buffer Overflow
CVE-2011-026710 ene 2011
Multiple buffer overflows in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allow remote at
60RIESGO
abrir
Metasploit300
HP Data Protector Manager RDS DOS
CVE-2011-051408 ene 2011
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash)
50RIESGO
abrir
Metasploit200
NetSupport Manager Agent Remote Buffer Overflow
CVE-2011-040408 ene 2011
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RIESGO
abrir
Metasploit300
Synology Forget Password User Enumeration Scanner
CVE-2017-955405 ene 2011
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Metasploit600
Axis2 / SAP BusinessObjects Authenticated Code Execution (via SOAP)
CVE-2010-021930 dic 2010
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
Metasploit400
Kolibri HTTP Server HEAD Buffer Overflow
CVE-2002-226826 dic 2010
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RIESGO
abrir
Metasploit300
Microsoft IIS FTP Server Encoded Response Overflow Trigger
CVE-2010-397221 dic 2010
Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0
60RIESGO
abrir
Metasploit600
Citrix Access Gateway Command Execution
CVE-2010-456621 dic 2010
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and
43RIESGO
abrir
Metasploit500
Microsoft WMI Administration Tools ActiveX Buffer Overflow
CVE-2010-397321 dic 2010
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in
60RIESGO
abrir
Metasploit600
Redmine SCM Repository Arbitrary Command Execution
CVE-2011-492919 dic 2010
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attacke
50RIESGO
abrir
Metasploit500
MS11-006 Microsoft Windows CreateSizedDIBSECTION Stack Buffer Overflow
CVE-2010-397015 dic 2010
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RIESGO
abrir
Metasploit300
Crystal Reports CrystalPrintControl ActiveX ServerResourceVersion Property Overflow
CVE-2010-259014 dic 2010
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RIESGO
abrir
Metasploit600
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
CVE-2010-396414 dic 2010
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Serve
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.