Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DB
Simple E-document 1.31 - Authentication Bypass
CVE-2014-10020webappsphp23 ene 2014
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DB
iTechClassifieds 3.03.057 - SQL Injection
CVE-2014-100020webappsphp23 ene 2014
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
GoToMeeting for Android - Multiple Local Information Disclosure Vulnerabilities
CVE-2014-1664localandroid23 ene 2014
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a
23RIESGO
abrir
Metasploit600
Simple E-Document Arbitrary File Upload
CVE-2014-125126CRITICAL23 ene 2014
Simple E-Document Arbitrary File Upload RCE
63RIESGO
abrir
Metasploit600
GE Proficy CIMPLICITY gefebt.exe Remote Code Execution
CVE-2014-075023 ene 2014
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir
Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
CVE-2015-080220 ene 2014
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir
Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
CVE-2014-863620 ene 2014
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir
Exploit-DBVexDay Proof
MuPDF 1.3 - 'xps_parse_color()' Stack Buffer Overflow
CVE-2014-2013localwindows20 ene 2014
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote a
28RIESGO
abrir
Exploit-DB
Teracom Modem T2-B-Gawv1.4U10Y-BI - Persistent Cross-Site Scripting
CVE-2014-10018webappshardware20 ene 2014
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem
23RIESGO
abrir
Exploit-DB
ASUS RT-N56U - Remote Buffer Overflow (ROP)
CVE-2013-6343remotehardware19 ene 2014
Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow
23RIESGO
abrir
Metasploit300
Mac OS X Safari file:// Redirection Sandbox Escape
CVE-2015-115516 ene 2014
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Sexy polling 1.0.8 - 'answer_id' SQL Injection
CVE-2013-7219webappsphp16 ene 2014
SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a
23RIESGO
abrir
Metasploit500
Oracle Forms and Reports Remote Code Execution
CVE-2012-3152CRITICALbajo ataque15 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir
Metasploit500
Oracle Forms and Reports Remote Code Execution
CVE-2012-315315 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir
Exploit-DB
Collabtive 1.1 - 'managetimetracker.php' SQL Injection
CVE-2013-6872webappsphp15 ene 2014
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu
23RIESGO
abrir
Exploit-DB
PHPJabbers Appointment Scheduler 2.0 - Multiple Vulnerabilities
CVE-2014-10001webappsphp14 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Atmail Webmail Server - Email Body HTML Injection
CVE-2013-6017webappsphp14 ene 2014
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Supply Chain Products Suite - Remote Security
CVE-2013-5880remotemultiple14 ene 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir
Exploit-DB
Conceptronic Wireless Pan & Tilt Network Camera - Cross-Site Request Forgery
CVE-2013-7204webappshardware14 ene 2014
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21
28RIESGO
abrir
Exploit-DB
Burden 1.8 - Authentication Bypass
CVE-2013-7137webappsphp14 ene 2014
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and
28RIESGO
abrir
Exploit-DB
SoapUI 4.6.3 - Remote Code Execution
CVE-2014-1202remotewindows14 ene 2014
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a c
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
CVE-2013-2251CRITICALbajo ataquewebappsmultiple14 ene 2014
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir
Exploit-DBVexDay Proof
SerComm Device - Remote Code Execution (Metasploit)
CVE-2014-0659remotehardware14 ene 2014
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir
Metasploit400
KingScada kxClientDownload.ocx ActiveX Remote Code Execution
CVE-2013-282714 ene 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir
Exploit-DB
Horizon QCMS 4.0 - Multiple Vulnerabilities
CVE-2013-7139webappsphp14 ene 2014
SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows rem
23RIESGO
abrir
Exploit-DB
PHPJabbers Event Booking Calendar 2.0 - Multiple Vulnerabilities
CVE-2014-10014webappsphp14 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attacke
23RIESGO
abrir
Exploit-DB
PHPJabbers Appointment Scheduler 2.0 - Multiple Vulnerabilities
CVE-2014-10010webappsphp14 ene 2014
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary file
23RIESGO
abrir
Exploit-DB
PHPJabbers Event Booking Calendar 2.0 - Multiple Vulnerabilities
CVE-2014-10015webappsphp14 ene 2014
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to exe
23RIESGO
abrir
Exploit-DB
Linux Kernel (Ubuntu 11.10/12.04) - binfmt_script Stack Data Disclosure
CVE-2012-4530doslinux14 ene 2014
The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, whic
23RIESGO
abrir
Exploit-DBVexDay Proof
Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections
CVE-2014-1671webappsphp13 ene 2014
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot
23RIESGO
abrir
anteriorpágina 1117 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.