Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Metasploit300
Apache Commons FileUpload and Apache Tomcat DoS
CVE-2014-005006 feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir
GitHub PoC8
Android Data Stealing Vulnerability
CVE-2010-480406 feb 2014
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// UR
43RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple05 feb 2014
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir
Metasploit300
Publish-It PUI Buffer Overflow (SEH)
CVE-2014-098005 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Metasploit300
Adobe Flash Player Integer Underflow Remote Code Execution
CVE-2014-0497HIGHbajo ataque05 feb 2014
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RIESGO
abrir
Exploit-DB
ownCloud 6.0.0a - Multiple Vulnerabilities
CVE-2014-1665webappsphp05 feb 2014
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RIESGO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7052webappshardware05 feb 2014
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
28RIESGO
abrir
Exploit-DBVexDay Proof
Skybluecanvas CMS - Remote Code Execution (Metasploit)
CVE-2014-1683remotelinux05 feb 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir
Exploit-DBVexDay Proof
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
CVE-2008-1461remotewindows05 feb 2014
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename arg
28RIESGO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7055webappshardware05 feb 2014
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts - Developer Mode OGNL Execution (Metasploit)
CVE-2012-0394remotejava05 feb 2014
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7053webappshardware05 feb 2014
D-Link DIR-100 4.03B07: cli.cgi CSRF
23RIESGO
abrir
Exploit-DB
VideoLAN VLC Media Player 2.1.2 - '.asf' Crash (PoC)
CVE-2014-1684dosmultiple05 feb 2014
The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Playe
23RIESGO
abrir
Exploit-DBVexDay Proof
ImpressCMS 1.3.5 - Multiple Vulnerabilities
CVE-2014-1836webappsphp05 feb 2014
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows
23RIESGO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7051webappshardware05 feb 2014
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
28RIESGO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7054webappshardware05 feb 2014
D-Link DIR-100 4.03B07: cli.cgi XSS
23RIESGO
abrir
Exploit-DB
TopicsViewer 3.0 Beta 1 - Multiple Vulnerabilities
CVE-2014-10023webappsphp05 feb 2014
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/reboot.cgi' Remote Reboot (Denial of Service)
CVE-2013-7183doscgi03 feb 2014
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) v
23RIESGO
abrir
Metasploit600
Array Networks vAPV and vxAG Private Key Privilege Escalation Code Execution
CVE-2014-125121CRITICAL03 feb 2014
Array Networks vAPV and vxAG Default Credential Privilege Escalation
43RIESGO
abrir
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/diagnostic.cgi?ping_ipaddr' Remote Code Execution
CVE-2013-7179remotecgi03 feb 2014
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.04/13.10 x64) - 'CONFIG_X86_X32=y' Local Privilege Escalation (3)
CVE-2014-0038locallinux_x86-6402 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
GitHub PoC199
Linux local root exploit for CVE-2014-0038
CVE-2014-003802 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Metasploit400
Linux Kernel recvmmsg Privilege Escalation
CVE-2014-003802 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.10) - 'CONFIG_X86_X32' Arbitrary Write (2)
CVE-2014-0038locallinux02 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
MediaWiki 1.22.1 PdfHandler - Remote Code Execution
CVE-2014-1610webappsmultiple01 feb 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir
Metasploit600
Pandora FMS Default Credential / SQLi Remote Code Execution
CVE-2014-125115CRITICAL01 feb 2014
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RIESGO
abrir
Exploit-DB
Linux Kernel 3.4 < 3.13.2 - recvmmsg x32 compat (PoC)
CVE-2014-0038doslinux31 ene 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Metasploit600
Zpanel Remote Unauthenticated RCE
CVE-2013-209730 ene 2014
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir
Metasploit600
Pandora FMS Remote Code Execution
CVE-2014-125124CRITICAL29 ene 2014
Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection
63RIESGO
abrir
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
CVE-2012-3153remotejsp29 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir
anteriorpágina 1115 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.