Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Metasploit600
ManageEngine Desktop Central AgentLogUpload Arbitrary File Upload
CVE-2013-739011 nov 2013
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-3528webappsphp08 nov 2013
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4467remotelinux08 nov 2013
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RIESGO
abrir
Metasploit300
MS13-090 CardSpaceClaimCollection ActiveX Integer Underflow
CVE-2013-3918HIGHbajo ataque08 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5038webappshardware08 nov 2013
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP a
23RIESGO
abrir
Exploit-DBVexDay Proof
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2)
CVE-2013-6364webappsphp08 nov 2013
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5220webappshardware08 nov 2013
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device
23RIESGO
abrir
Exploit-DB
appRain 3.0.2 - Blind SQL Injection
CVE-2013-6058webappsphp08 nov 2013
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5218webappshardware08 nov 2013
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-7382remotelinux08 nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5219webappshardware08 nov 2013
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Vivotek IP Cameras - RTSP Authentication Bypass
CVE-2013-4985webappshardware08 nov 2013
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4468remotelinux08 nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5039webappshardware08 nov 2013
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.1
23RIESGO
abrir
Exploit-DB
Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injection
CVE-2013-6164webappsphp08 nov 2013
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-2749webappsphp08 nov 2013
20RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5037webappshardware08 nov 2013
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers
23RIESGO
abrir
Metasploit300
IBM Lotus Sametime WebPlayer DoS
CVE-2013-398607 nov 2013
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension c
18RIESGO
abrir
Metasploit400
Supermicro Onboard IPMI close_window.cgi Buffer Overflow
CVE-2013-362306 nov 2013
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir
Metasploit300
Supermicro Onboard IPMI CGI Vulnerability Scanner
CVE-2013-362106 nov 2013
15RIESGO
abrir
Metasploit300
Supermicro Onboard IPMI CGI Vulnerability Scanner
CVE-2013-362306 nov 2013
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir
Metasploit300
Supermicro Onboard IPMI Static SSL Certificate Scanner
CVE-2013-361906 nov 2013
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_3
18RIESGO
abrir
Metasploit300
Supermicro Onboard IPMI url_redirect.cgi Authenticated Directory Traversal
CVE-2013-678506 nov 2013
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attacker
18RIESGO
abrir
Metasploit200
MS13-096 Microsoft Tagged Image File Format (TIFF) Integer Overflow
CVE-2013-3906HIGHbajo ataque05 nov 2013
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RIESGO
abrir
Exploit-DBVexDay Proof
Hanso Player 2.5.0 - 'm3u' Buffer Overflow (Denial of Service)
CVE-2013-7280doswindows05 nov 2013
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Signature Verification Security Bypass
CVE-2013-6792remoteandroid04 nov 2013
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
23RIESGO
abrir
Metasploit600
Gitlab-shell Code Execution
CVE-2013-449004 nov 2013
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x
50RIESGO
abrir
Exploit-DB
Apache Tomcat 5.5.25 - Cross-Site Request Forgery
CVE-2013-6357webappsmultiple04 nov 2013
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows re
23RIESGO
abrir
Metasploit300
Watermark Master Buffer Overflow (SEH)
CVE-2013-693501 nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - Local Buffer Overflow (SEH)
CVE-2013-6935localwindows01 nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir
anteriorpágina 1124 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.