Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit)
CVE-2013-3115remotewindows10 sep 2013
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit)
CVE-2013-3149remotewindows10 sep 2013
Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memo
28RIESGO
abrir
Exploit-DBVexDay Proof
AjaXplorer 1.0 - Multiple Vulnerabilities
CVE-2013-5688webappsphp10 sep 2013
Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated use
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit)
CVE-2013-3153remotewindows10 sep 2013
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit)
CVE-2013-3162remotewindows10 sep 2013
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CAnchorElement Use-After-Free (MS13-055) (Metasploit)
CVE-2013-3161remotewindows10 sep 2013
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (mem
28RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance - Multiple Vulnerabilities
CVE-2013-4983webappslinux09 sep 2013
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows
60RIESGO
abrir
Metasploit600
HP ProCurve Manager SNAC UpdateCertificatesServlet File Upload
CVE-2013-481209 sep 2013
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0,
50RIESGO
abrir
Metasploit600
HP ProCurve Manager SNAC UpdateDomainControllerServlet File Upload
CVE-2013-481109 sep 2013
UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4
60RIESGO
abrir
Exploit-DB
Moodle 2.3.8/2.4.5 - Multiple Vulnerabilities
CVE-2013-4341webappsphp09 sep 2013
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an
43RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance - Multiple Vulnerabilities
CVE-2013-4984webappslinux09 sep 2013
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1
38RIESGO
abrir
GitHub PoC9
Meatballs1/cve-2013-1300
CVE-2013-130009 sep 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2013-130009 sep 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir
Exploit-DBVexDay Proof
Watchguard Server Center - Local Privilege Escalation
CVE-2013-5701localwindows08 sep 2013
Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebB
23RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5377localwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the t
23RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5381localwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in PHP 5.3.17, when installed in the top-level C:\
23RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5380MEDIUMlocalwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-leve
33RIESGO
abrir
Metasploit600
Sophos Web Protection Appliance clear_keys.pl Local Privilege Escalation
CVE-2013-498406 sep 2013
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1
38RIESGO
abrir
Metasploit600
Android get_user/put_user Exploit
CVE-2013-6282HIGHbajo ataque06 sep 2013
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5378localwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in ActiveTcl 8.5.12, when installed in the top-lev
23RIESGO
abrir
Metasploit600
Sophos Web Protection Appliance sblistpack Arbitrary Command Execution
CVE-2013-498306 sep 2013
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows
60RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5379HIGHlocalwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top
41RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5383localwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-
23RIESGO
abrir
Exploit-DBVexDay Proof
IKE and AuthIP IPsec Keyring Modules Service (IKEEXT) - Missing DLL (Metasploit)
CVE-2012-5382localwindows06 sep 2013
Untrusted search path vulnerability in the installation functionality in Zend Server 5.6.0 SP4, when installed in the to
23RIESGO
abrir
Metasploit300
HTTP Client LAN IP Address Gather
CVE-2018-684905 sep 2013
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
43RIESGO
abrir
Metasploit600
Red Hat CloudForms Management Engine 5.1 agent/linuxpkgs Path Traversal
CVE-2013-206804 sep 2013
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow re
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CFlatMarkupPointer Use-After-Free (MS13-059) (Metasploit)
CVE-2013-3184remotewindows04 sep 2013
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
50RIESGO
abrir
Exploit-DBVexDay Proof
KingView 6.53 - 'SuperGrid' Insecure ActiveX Control
CVE-2013-6127localwindows04 sep 2013
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53
28RIESGO
abrir
Exploit-DBVexDay Proof
HP LoadRunner - lrFileIOService ActiveX WriteFileString Remote Code Execution (Metasploit)
CVE-2013-4798remotewindows04 sep 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RIESGO
abrir
Exploit-DB
Apple Safari 6.0.1 for iOS 6.0 / Apple Mac OSX 10.7/8 - Heap Buffer Overflow
CVE-2012-3748remoteios04 sep 2013
Race condition in WebKit in Apple iOS before 6.0.1 and Safari before 6.0.2 allows remote attackers to execute arbitrary
28RIESGO
abrir
anteriorpágina 1131 / 2707siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.