Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DB
Nisuta NS-WIR150NE / NS-WIR300N Wireless Routers - Remote Management Web Interface Authentication Bypass
CVE-2013-7282webappshardware03 ene 2014
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with fi
23RIESGO
abrir
Exploit-DB
Technicolor TC7200 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2014-0620webappshardware03 ene 2014
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote att
23RIESGO
abrir
Exploit-DB
Technicolor TC7200 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2014-0621webappshardware03 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow rem
23RIESGO
abrir
Metasploit600
HP Data Protector Backup Client Service Remote Code Execution
CVE-2013-234702 ene 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir
Metasploit500
HP Client Automation Command Injection
CVE-2015-149702 ene 2014
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Metasploit500
HP Data Protector Backup Client Service Directory Traversal
CVE-2013-619402 ene 2014
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Libcloud Digital Ocean API - Local Information Disclosure
CVE-2013-6480locallinux01 ene 2014
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows loca
23RIESGO
abrir
Metasploit500
SerComm Device Remote Code Execution
CVE-2014-065931 dic 2013
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir
Metasploit300
SerComm Network Device Backdoor Detection
CVE-2014-065931 dic 2013
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory Traversal
CVE-2013-7240webappsphp30 dic 2013
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote
43RIESGO
abrir
Exploit-DBVexDay Proof
CMS Afroditi - 'id' SQL Injection
CVE-2013-7278webappsasp30 dic 2013
SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Metasploit300
IBM Lotus Sametime Version Enumeration
CVE-2013-398227 dic 2013
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspeci
23RIESGO
abrir
Metasploit300
IBM Lotus Notes Sametime User Enumeration
CVE-2013-397527 dic 2013
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remot
23RIESGO
abrir
Metasploit300
IBM Lotus Notes Sametime Room Name Bruteforce
CVE-2013-397727 dic 2013
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine whic
18RIESGO
abrir
Exploit-DBVexDay Proof
JForum 'adminUsers' Module - Cross-Site Request Forgery
CVE-2013-7209webappsphp26 dic 2013
Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
HP SiteScope issueSiebelCmd - Remote Code Execution (Metasploit)
CVE-2013-4835remoteunix24 dic 2013
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RIESGO
abrir
Exploit-DBVexDay Proof
OpenSIS 'modname' - PHP Code Execution (Metasploit)
CVE-2013-1349remotelinux24 dic 2013
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP cod
43RIESGO
abrir
Exploit-DBVexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
CVE-2013-7260localwindows24 dic 2013
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RIESGO
abrir
Exploit-DBVexDay Proof
Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit)
CVE-2013-7091webappslinux24 dic 2013
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir
Exploit-DBVexDay Proof
Synology DiskStation Manager - SLICEUPLOAD Remote Command Execution (Metasploit)
CVE-2013-6955remoteunix24 dic 2013
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RIESGO
abrir
Exploit-DBVexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
CVE-2013-6877localwindows24 dic 2013
Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738
28RIESGO
abrir
Exploit-DB
Synology DSM 4.3-3810 - Directory Traversal
CVE-2013-6987webappscgi24 dic 2013
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RIESGO
abrir
Exploit-DB
Huawei Technologies du Mobile Broadband 16.0 - Local Privilege Escalation
CVE-2014-8358localwindows24 dic 2013
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)
23RIESGO
abrir
Exploit-DB
Huawei Technologies du Mobile Broadband 16.0 - Local Privilege Escalation
CVE-2014-8359localwindows24 dic 2013
Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
RedHat CloudForms Management Engine 5.1 - agent/linuxpkgs Directory Traversal (Metasploit)
CVE-2013-2068remotelinux24 dic 2013
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow re
50RIESGO
abrir
GitHub PoC12
Using CVE-2013-6282 to bypass Samsung kernel module authentication
CVE-2013-6282HIGHbajo ataque21 dic 2013
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DB
Cisco EPC3925 - Persistent Cross-Site Scripting
CVE-2013-6976webappshardware21 dic 2013
Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers t
23RIESGO
abrir
VulnCheck XDB
local
CVE-2013-6282HIGHbajo ataque21 dic 2013
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DB
PotPlayer 1.5.40688 - '.avi' File Handling Memory Corruption
CVE-2013-7185doswindows20 dic 2013
PotPlayer 1.5.40688: .avi File Memory Corruption
23RIESGO
abrir
Exploit-DB
GOM Player 2.2.56.5158 - '.avi' File Handling Memory Corruption
CVE-2013-7184doswindows20 dic 2013
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption
23RIESGO
abrir
anteriorpágina 1119 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.