Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DB
SpagoBI 4.0 - Persistent HTML Script Insertion
CVE-2013-6233webappsphp03 mar 2014
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
ALLPlayer 5.8.1 - '.m3u' Local Buffer Overflow (SEH)
CVE-2013-7409localwindows03 mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10035webappsphp03 mar 2014
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RIESGO
abrir
Exploit-DB
SpagoBI 4.0 - Arbitrary Cross-Site Scripting / Arbitrary File Upload
CVE-2013-6234webappsphp03 mar 2014
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users
23RIESGO
abrir
Exploit-DBVexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
CVE-2014-10034webappsphp03 mar 2014
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RIESGO
abrir
Exploit-DB
SpagoBI 4.0 - Persistent Cross-Site Scripting
CVE-2013-6232webappsphp03 mar 2014
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RIESGO
abrir
Metasploit300
Joomla weblinks-categories Unauthenticated SQL Injection Arbitrary File Read
CVE-2014-798102 mar 2014
SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL
18RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Database Credentials Disclosure
CVE-2013-5795webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
CVE-2013-5877webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - SQL Injection
CVE-2014-0372webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
CVE-2014-0379webappswindows01 mar 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RIESGO
abrir
Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
CVE-2013-6041webappsphp28 feb 2014
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharact
23RIESGO
abrir
Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
CVE-2014-1906webappsphp28 feb 2014
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5
23RIESGO
abrir
Exploit-DB
SpagoBI 4.0 - Privilege Escalation
CVE-2013-6231webappsmultiple28 feb 2014
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
23RIESGO
abrir
Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
CVE-2014-1908webappsphp28 feb 2014
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Li
23RIESGO
abrir
Exploit-DB
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
CVE-2014-9304webappsmultiple28 feb 2014
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and e
23RIESGO
abrir
Exploit-DB
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
CVE-2014-9181webappsmultiple28 feb 2014
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrar
23RIESGO
abrir
Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
CVE-2014-1907webappsphp28 feb 2014
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor
28RIESGO
abrir
Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
CVE-2013-6043webappsphp28 feb 2014
The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attem
23RIESGO
abrir
Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
CVE-2014-1905webappsphp28 feb 2014
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo
23RIESGO
abrir
Exploit-DBVexDay Proof
VCDGear 3.50 - '.cue' Local Stack Buffer Overflow
CVE-2007-2568localwindows28 feb 2014
Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via
23RIESGO
abrir
Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
CVE-2013-6042webappsphp28 feb 2014
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo befor
23RIESGO
abrir
Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
CVE-2013-587728 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir
Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
CVE-2013-588028 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir
Exploit-DBVexDay Proof
GE Proficy CIMPLICITY - 'gefebt.exe' Remote Code Execution (Metasploit)
CVE-2014-0750remotewindows28 feb 2014
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir
Metasploit300
MantisBT Admin SQL Injection Arbitrary File Read
CVE-2014-223828 feb 2014
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 a
23RIESGO
abrir
Metasploit300
Oracle Demantra Database Credentials Leak
CVE-2013-579528 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir
Metasploit300
Oracle Demantra Database Credentials Leak
CVE-2013-588028 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir
Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
CVE-2014-100029webappsphp27 feb 2014
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote atta
23RIESGO
abrir
Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
CVE-2014-100030webappsphp27 feb 2014
Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remot
23RIESGO
abrir
anteriorpágina 1112 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.