Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
CVE-2013-5639webappsphp02 oct 2013
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALbajo ataqueransomware01 oct 2013
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
Exploit-DB
glibc and eglibc 2.5/2.7/2.13 - Local Buffer Overflow
CVE-2013-4788locallinux30 sep 2013
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLI
28RIESGO
abrir
Exploit-DB
SimpleRisk 20130915-01 - Multiple Vulnerabilities
CVE-2013-5748webappsphp30 sep 2013
Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001
23RIESGO
abrir
Exploit-DB
mod_accounting Module 0.5 - Blind SQL Injection
CVE-2013-5697webappslinux30 sep 2013
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Nodejs - 'js-yaml load()' Code Exec (Metasploit)
CVE-2013-4660localmultiple30 sep 2013
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, whic
43RIESGO
abrir
Exploit-DB
XAMPP 1.8.1 - 'lang.php?WriteIntoLocalDisk method' Local Write Access
CVE-2013-2586webappsphp30 sep 2013
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp
23RIESGO
abrir
Exploit-DB
Hewlett-Packard (HP) 2620 Switch Series. Edit Admin Account - Cross-Site Request Forgery
CVE-2013-6852webappshardware26 sep 2013
Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack
23RIESGO
abrir
Exploit-DB
X2CRM 3.4.1 - Multiple Vulnerabilities
CVE-2013-5692webappsphp25 sep 2013
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and
23RIESGO
abrir
Exploit-DB
X2CRM 3.4.1 - Multiple Vulnerabilities
CVE-2013-5693webappsphp25 sep 2013
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DB
Good for Enterprise 2.2.2.1611 - Cross-Site Scripting
CVE-2013-5118webappshardware25 sep 2013
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attacker
23RIESGO
abrir
Metasploit600
ibstat $PATH Privilege Escalation
CVE-2013-401124 sep 2013
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir
Exploit-DBVexDay Proof
IBM AIX 6.1/7.1 - Local Privilege Escalation
CVE-2013-4011localaix24 sep 2013
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CCaret Use-After-Free (MS13-069) (Metasploit)
CVE-2013-3205remotewindows23 sep 2013
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (
50RIESGO
abrir
Metasploit600
Zabbix 2.0.8 SQL Injection and Remote Code Execution
CVE-2013-574323 sep 2013
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
60RIESGO
abrir
Exploit-DB
WordPress Plugin NOSpamPTI - Blind SQL Injection
CVE-2013-5917webappsphp23 sep 2013
SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Theme File Handling - Arbitrary Code Execution (MS13-071) (Metasploit)
CVE-2013-0810HIGHremotewindows23 sep 2013
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote a
68RIESGO
abrir
Exploit-DBVexDay Proof
Linksys WRT110 - Remote Command Execution (Metasploit)
CVE-2013-3568remotehardware23 sep 2013
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentica
43RIESGO
abrir
Exploit-DBVexDay Proof
GLPI - 'install.php' Remote Command Execution (Metasploit)
CVE-2013-5696remotephp23 sep 2013
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installati
38RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Lazy SEO 1.1.9 - Arbitrary File Upload
CVE-2013-5961webappsphp22 sep 2013
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers
23RIESGO
abrir
Metasploit600
ZeroShell Remote Code Execution
CVE-2009-054522 sep 2013
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell meta
60RIESGO
abrir
GitHub PoC411
Debian OpenSSL Predictable PRNG (CVE-2008-0166)
CVE-2008-016622 sep 2013
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir
Exploit-DB
vTiger CRM 5.4.0 - 'index.php?onlyforuser' SQL Injection
CVE-2013-5091webappsphp20 sep 2013
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated u
23RIESGO
abrir
Exploit-DB
WordPress Plugin Complete Gallery Manager 3.3.3 - Arbitrary File Upload
CVE-2013-5962webappsphp18 sep 2013
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r
28RIESGO
abrir
Metasploit600
Cisco Prime Data Center Network Manager Arbitrary File Upload
CVE-2013-548618 sep 2013
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir
Metasploit600
F5 iControl Remote Root Command Execution
CVE-2014-292817 sep 2013
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5
50RIESGO
abrir
Metasploit300
MS13-080 Microsoft Internet Explorer SetMouseCapture Use-After-Free
CVE-2013-3893HIGHbajo ataque17 sep 2013
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RIESGO
abrir
Metasploit0
Astium Remote Code Execution
CVE-2013-10043CRITICAL17 sep 2013
Astium VOIP PBX <= 2.1 SQL Injection File Upload RCE
63RIESGO
abrir
Exploit-DBVexDay Proof
HP ProCurve Manager SNAC - UpdateCertificatesServlet Arbitrary File Upload (Metasploit)
CVE-2013-4812remotewindows17 sep 2013
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0,
50RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance - 'sblistpack' Arbitrary Command Execution (Metasploit)
CVE-2013-4983remotelinux17 sep 2013
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows
60RIESGO
abrir
anteriorpágina 1129 / 2707siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.