Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Exploit-DBVexDay Proof
vBulletin 4.1.x - '/install/upgrade.php' Security Bypass
CVE-2013-6129webappsphp13 oct 2013
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the
50RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet FortiAnalyzer - Cross-Site Request Forgery
CVE-2013-6826remotehardware12 oct 2013
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate th
23RIESGO
abrir
Metasploit300
Beetel Connection Manager NetConfig.ini Buffer Overflow
CVE-2013-10036HIGH12 oct 2013
Beetel Connection Manager NetConfig.ini Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit300
Android Settings Remove Device Locks (4.0-4.3)
CVE-2013-627111 oct 2013
Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted ap
18RIESGO
abrir
Exploit-DBVexDay Proof
IBM Cognos Business Intelligence - XML External Entity Information Disclosure
CVE-2013-4034remotemultiple11 oct 2013
IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 befor
23RIESGO
abrir
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' Local Buffer Overflow (PoC)
CVE-2013-7409doswindows10 oct 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Exploit-DBVexDay Proof
Bugzilla 4.2 - Tabular Reports Cross-Site Scripting
CVE-2013-1743webappscgi09 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and
23RIESGO
abrir
Exploit-DBVexDay Proof
Bugzilla - 'editflagtypes.cgi' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-1742webappscgi09 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11;
23RIESGO
abrir
Metasploit300
vBulletin Administrator Account Creation
CVE-2013-612909 oct 2013
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the
50RIESGO
abrir
Metasploit300
ALLPlayer M3U Buffer Overflow
CVE-2013-740909 oct 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Metasploit300
HP Intelligent Management SOM Account Creation
CVE-2013-482408 oct 2013
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Mod
23RIESGO
abrir
Metasploit300
MS13-080 Microsoft Internet Explorer CDisplayPointer Use-After-Free
CVE-2013-3897HIGHbajo ataque08 oct 2013
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo
100RIESGO
abrir
Metasploit600
HP Intelligent Management Center BIMS UploadServlet Directory Traversal
CVE-2013-482208 oct 2013
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
50RIESGO
abrir
Metasploit200
Windows TrackPopupMenuEx Win32k NULL Page
CVE-2013-388108 oct 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RIESGO
abrir
Exploit-DBVexDay Proof
HP LoadRunner - 'magentproc.exe' Remote Overflow (Metasploit)
CVE-2013-4800remotewindows08 oct 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RIESGO
abrir
Exploit-DB
Apple Motion 5.0.7 - Integer Overflow
CVE-2013-6114dososx08 oct 2013
Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denia
23RIESGO
abrir
Exploit-DBVexDay Proof
davfs2 1.4.6/1.4.7 - Local Privilege Escalation
CVE-2013-4362locallinux08 oct 2013
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat/JBoss EJBInvokerServlet / JMXInvokerServlet (RMI over HTTP) Marshalled Object - Remote Code Execution
CVE-2013-4810CRITICALbajo ataqueremotephp04 oct 2013
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle
100RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD 9.0 - Intel SYSRET Kernel Privilege Escalation
CVE-2012-0217localfreebsd04 oct 2013
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RIESGO
abrir
Metasploit600
FlashChat Arbitrary File Upload
CVE-2013-10038CRITICAL04 oct 2013
FlashChat Arbitrary File Upload RCE
63RIESGO
abrir
Metasploit600
GestioIP Remote Command Execution
CVE-2013-10039HIGH04 oct 2013
GestioIP 3.0 ip_checkhost.cgi RCE
36RIESGO
abrir
Metasploit600
ClipBucket Remote Code Execution
CVE-2013-10040CRITICAL04 oct 2013
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
63RIESGO
abrir
VulnCheck XDB
local
CVE-2013-259503 oct 2013
The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm
23RIESGO
abrir
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-7349webappsphp02 oct 2013
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Exploit-DBVexDay Proof
GLPI 0.84.1 - Multiple Vulnerabilities
CVE-2013-5696webappsphp02 oct 2013
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installati
38RIESGO
abrir
Exploit-DBVexDay Proof
PinApp Mail-SeCure 3.70 - Access Control Failure
CVE-2013-4987locallinux02 oct 2013
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and pr
23RIESGO
abrir
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-5640webappsphp02 oct 2013
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Exploit-DBVexDay Proof
Micorosft Internet Explorer - SetMouseCapture Use-After-Free (Metasploit)
CVE-2013-3893HIGHbajo ataqueremotewindows02 oct 2013
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RIESGO
abrir
Exploit-DBVexDay Proof
HylaFAX+ 5.2.4 > 5.5.3 - Buffer Overflow
CVE-2013-5680doslinux02 oct 2013
Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote
23RIESGO
abrir
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-5639webappsphp02 oct 2013
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir
anteriorpágina 1128 / 2707siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.