Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Metasploit300
IBM Forms Viewer Unicode Buffer Overflow
CVE-2013-544705 dic 2013
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RIESGO
abrir
Exploit-DB
SonicWALL Gms 7.x - Filter Bypass / Persistent
CVE-2013-7025webappsjsp05 dic 2013
Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell So
23RIESGO
abrir
Metasploit300
Ruby on Rails Action View MIME Memory Exhaustion
CVE-2013-641404 dic 2013
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allo
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 5.0.x - IF Query Handling Remote Denial of Service
CVE-2007-2583doslinux04 dic 2013
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RIESGO
abrir
Exploit-DBVexDay Proof
Steinberg MyMp3PRO 5.0 - Local Buffer Overflow (SEH) (DEP Bypass + ROP)
CVE-2013-7186localwindows04 dic 2013
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Exploit-DBVexDay Proof
Chamilo Lms 1.9.6 - 'profile.php?password' SQL Injection
CVE-2013-6787webappsphp03 dic 2013
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlie
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'NDPROXY' SYSTEM Privilege Escalation (MS14-002)
CVE-2013-5065HIGHbajo ataquelocalwindows03 dic 2013
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Prime Data Center Network Manager - Arbitrary File Upload (Metasploit)
CVE-2013-5486remotejava03 dic 2013
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
CVE-2013-3906HIGHbajo ataqueremotewindows03 dic 2013
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RIESGO
abrir
Exploit-DB
Dokeos 2.2 RC2 - 'index.php?language' SQL Injection
CVE-2013-6341webappsphp03 dic 2013
SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Formcraft - SQL Injection
CVE-2013-7187webappsphp02 dic 2013
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers
23RIESGO
abrir
Metasploit200
Windows NTUserMessageCall Win32k Kernel Pool Overflow (Schlamperei)
CVE-2013-130001 dic 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir
Exploit-DB
TVT TD-2308SS-B DVR - Directory Traversal
CVE-2013-6023webappshardware01 dic 2013
Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote at
28RIESGO
abrir
Exploit-DBVexDay Proof
Kingsoft Office Writer 2012 8.1.0.3385 - '.wps' Local Buffer Overflow (SEH)
CVE-2013-3934localwindows30 nov 2013
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allow
23RIESGO
abrir
Exploit-DB
Scientific-Atlanta_ Inc. DPR2320R2 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2013-7043webappshardware30 nov 2013
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2
23RIESGO
abrir
Metasploit600
WordPress OptimizePress Theme File Upload Vulnerability
CVE-2013-710229 nov 2013
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-
23RIESGO
abrir
GitHub PoC8
CVE-2013-6282 exploit
CVE-2013-6282HIGHbajo ataque28 nov 2013
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader - ASLR + DEP Bypass with Sandbox Bypass
CVE-2013-0640HIGHbajo ataquelocalwindows28 nov 2013
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CardSpaceClaimCollection ActiveX Integer Underflow (MS13-090) (Metasploit)
CVE-2013-3918HIGHbajo ataqueremotewindows27 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RIESGO
abrir
Metasploit200
MS14-002 Microsoft Windows ndproxy.sys Local Privilege Escalation
CVE-2013-5065HIGHbajo ataque27 nov 2013
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2012-0016remotewindows27 nov 2013
Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2013-0074HIGHbajo ataqueransomwareremotewindows27 nov 2013
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML obj
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Roller - OGNL Injection (Metasploit)
CVE-2013-4212remotejava27 nov 2013
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RIESGO
abrir
Exploit-DBVexDay Proof
DesktopCentral AgentLogUpload - Arbitrary File Upload (Metasploit)
CVE-2013-7390remotewindows25 nov 2013
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir
Exploit-DBVexDay Proof
Netgear ReadyNAS - Perl Code Evaluation (Metasploit)
CVE-2013-2751remotehardware25 nov 2013
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator
60RIESGO
abrir
Exploit-DBVexDay Proof
DesktopCentral AgentLogUpload - Arbitrary File Upload (Metasploit)
CVE-2014-5007remotewindows25 nov 2013
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RIESGO
abrir
Exploit-DB
ALLPlayer 5.7 - '.m3u' UNICODE Buffer Overflow (SEH)
CVE-2013-7409localwindows24 nov 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Metasploit300
Total Video Player 1.3.1 (Settings.ini) - SEH Buffer Overflow
CVE-2009-026124 nov 2013
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Ajaxfs 2 Plugin - SQL Injection
CVE-2013-6936webappsphp24 nov 2013
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Blue Wrench Video Widget - Cross-Site Request Forgery
CVE-2013-6797webappsphp23 nov 2013
Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin be
23RIESGO
abrir
anteriorpágina 1122 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.