Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DBVexDay Proof
OpenMediaVault Cron - Remote Command Execution (Metasploit)
CVE-2013-3632HIGHremotelinux31 oct 2013
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir
Metasploit600
Apache Roller OGNL Injection
CVE-2013-421231 oct 2013
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RIESGO
abrir
Exploit-DBVexDay Proof
ISPConfig - (Authenticated) Arbitrary PHP Code Execution (Metasploit)
CVE-2013-3629remotephp31 oct 2013
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RIESGO
abrir
Metasploit600
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution
CVE-2013-695531 oct 2013
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RIESGO
abrir
Exploit-DBVexDay Proof
Zabbix - (Authenticated) Remote Command Execution (Metasploit)
CVE-2013-3628remotelinux31 oct 2013
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir
Exploit-DBVexDay Proof
Moodle - Remote Command Execution (Metasploit)
CVE-2013-3630remotelinux31 oct 2013
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.3.0 5.4.0 - (Authenticated) Remote Code Execution (Metasploit)
CVE-2013-3591remotephp31 oct 2013
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RIESGO
abrir
Exploit-DBVexDay Proof
NAS4Free - Remote Code Execution (Metasploit)
CVE-2013-3631remotephp31 oct 2013
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RIESGO
abrir
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2311remotephp31 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir
Exploit-DB
Opsview pre 4.4.1 - Blind SQL Injection
CVE-2013-5694webappsphp31 oct 2013
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2336remotephp31 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-1823CRITICALbajo ataqueremotephp31 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
Metasploit600
HP LoadRunner EmulationAdmin Web Service Directory Traversal
CVE-2013-483730 oct 2013
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RIESGO
abrir
Metasploit500
Rocket Servergraph Admin Center fileRequestor Remote Code Execution
CVE-2014-391430 oct 2013
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RIESGO
abrir
Metasploit600
vTigerCRM v5.4.0/v5.3.0 Authenticated Remote Code Execution
CVE-2013-359130 oct 2013
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RIESGO
abrir
Metasploit600
OpenMediaVault rpc.php Authenticated Cron Remote Code Execution
CVE-2013-3632HIGH30 oct 2013
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir
Metasploit600
ISPConfig Authenticated Arbitrary PHP Code Execution
CVE-2013-362930 oct 2013
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RIESGO
abrir
Metasploit500
HP SiteScope issueSiebelCmd Remote Code Execution
CVE-2013-483530 oct 2013
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RIESGO
abrir
Metasploit500
NAS4Free Arbitrary Remote Code Execution
CVE-2013-363130 oct 2013
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RIESGO
abrir
Metasploit300
Openbravo ERP XXE Arbitrary File Read
CVE-2013-361730 oct 2013
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML
43RIESGO
abrir
Metasploit600
Moodle Authenticated Spelling Binary RCE
CVE-2013-434130 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an
43RIESGO
abrir
Metasploit600
Zabbix Authenticated Remote Command Execution
CVE-2013-362830 oct 2013
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir
Metasploit600
Moodle Authenticated Spelling Binary RCE
CVE-2013-363030 oct 2013
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RIESGO
abrir
Exploit-DBVexDay Proof
Openbravo ERP - XML External Entity Information Disclosure
CVE-2013-3617remotemultiple30 oct 2013
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML
43RIESGO
abrir
Exploit-DBVexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
CVE-2012-1823CRITICALbajo ataqueremotephp29 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
CVE-2012-2336remotephp29 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir
Exploit-DBVexDay Proof
Apache + PHP < 5.3.12 / < 5.4.2 - cgi-bin Remote Code Execution
CVE-2012-2311remotephp29 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir
Exploit-DB
Watchguard Firewall XTM 11.7.4u1 - Remote Buffer Overflow
CVE-2013-6021remotehardware29 oct 2013
Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code
28RIESGO
abrir
Exploit-DB
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (1)
CVE-2013-6275webappsphp29 oct 2013
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
23RIESGO
abrir
Exploit-DB
Stem Innovation - 'IZON' Hard-Coded Credentials
CVE-2013-6236webappshardware29 oct 2013
IZON IP 2.0.2: hard-coded password vulnerability
28RIESGO
abrir
anteriorpágina 1125 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.