Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
CVE-2012-3152CRITICALbajo ataqueremotejsp29 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
CVE-2012-3153remotejsp29 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'CWD' Remote Buffer Overflow
CVE-2013-4730remotewindows29 ene 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Exploit-DB
ManageEngine Support Center Plus 7916 - Directory Traversal
CVE-2014-100002webappsphp29 ene 2014
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RIESGO
abrir
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1631webappsphp28 ene 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RIESGO
abrir
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1632webappsphp28 ene 2014
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the
28RIESGO
abrir
Metasploit0
Kloxo SQL Injection and Remote Code Execution
CVE-2014-125123CRITICAL28 ene 2014
Kloxo < 6.1.12 Unauthenticated SQL Injection RCE
43RIESGO
abrir
Metasploit600
SkyBlueCanvas CMS Remote Code Execution
CVE-2014-168328 ene 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir
Metasploit300
A10 Networks AX Loadbalancer Directory Traversal
CVE-2014-125125HIGH28 ene 2014
A10 Networks AX Loadbalancer Path Traversal
36RIESGO
abrir
GitHub PoC8
Automated exploit for CVE-2012-3153 / CVE-2012-3152
CVE-2012-315328 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir
Metasploit600
MediaWiki Thumb.php Remote Command Execution
CVE-2014-161028 ene 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir
Metasploit300
ManageEngine Support Center Plus Directory Traversal
CVE-2014-10000228 ene 2014
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2012-315328 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir
Exploit-DBVexDay Proof
Eventum - Insecure File Permissions
CVE-2014-1631webappsphp27 ene 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RIESGO
abrir
Exploit-DB
Oracle Outside In MDB - File Parsing Stack Buffer Overflow (PoC)
CVE-2013-5791doswindows27 ene 2014
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allo
23RIESGO
abrir
Exploit-DB
Mozilla Thunderbird 17.0.6 - Input Validation Filter Bypass
CVE-2013-6674dosmultiple27 ene 2014
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1
23RIESGO
abrir
Exploit-DBVexDay Proof
MP3Info 0.8.5a - Buffer Overflow
CVE-2006-2465doslinux27 ene 2014
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RIESGO
abrir
Exploit-DB
Ammyy Admin 3.2 - Authentication Bypass
CVE-2013-5582localwindows24 ene 2014
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assiste
23RIESGO
abrir
Exploit-DBVexDay Proof
Daum Game 1.1.0.5 - ActiveX 'IconCreate Method' Remote Stack Buffer Overflow
CVE-2013-7246remotewindows24 ene 2014
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows
28RIESGO
abrir
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 ene 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RIESGO
abrir
Exploit-DB
MW6 Technologies MaxiCode - ActiveX 'Data' Buffer Overflow (PoC)
CVE-2013-6040HIGHdoswindows24 ene 2014
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RIESGO
abrir
Exploit-DB
MW6 Technologies Datamatrix - ActiveX 'Data' Buffer Overflow
CVE-2013-6040HIGHdoswindows24 ene 2014
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector - Backup Client Service Directory Traversal (Metasploit)
CVE-2013-6194remotewindows24 ene 2014
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir
Exploit-DB
Ammyy Admin 3.2 - Authentication Bypass
CVE-2013-5581localwindows24 ene 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Skybluecanvas CMS 1.1 r248-03 - Remote Command Execution
CVE-2014-1683webappsphp24 ene 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir
Exploit-DB
MW6 Technologies Aztec - ActiveX 'Data' Buffer Overflow (PoC)
CVE-2013-6040HIGHdoswindows24 ene 2014
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RIESGO
abrir
Exploit-DB
Joomla! Component JV Comment 3.0.2 - 'id' SQL Injection
CVE-2014-0794webappsphp24 ene 2014
SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authentic
23RIESGO
abrir
Exploit-DB
Joomla! Component Komento 1.7.2 - Persistent Cross-Site Scripting
CVE-2014-0793webappsphp24 ene 2014
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J
23RIESGO
abrir
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7247webappshardware24 ene 2014
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows
23RIESGO
abrir
Exploit-DB
iTechClassifieds 3.03.057 - SQL Injection
CVE-2014-100020webappsphp23 ene 2014
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary
23RIESGO
abrir
anteriorpágina 1116 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.