Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Metasploit600
VMWare Setuid vmware-mount Unsafe popen(3)
CVE-2013-1662—22 ago 2013
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RIESGO
abrir ↗
Exploit-DB
Samba 3.5.22/3.6.17/4.0.8 - nttrans Reply Integer Overflow
CVE-2013-4124—doslinux22 ago 2013
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
CVE-2008-4423—webappsphp22 ago 2013
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foreman (RedHat OpenStack/Satellite) - users/create Mass Assignment (Metasploit)
CVE-2013-2113—webappslinux22 ago 2013
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users w
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
CVE-2008-3918—webappsphp22 ago 2013
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB
Adobe ColdFusion 9 - Administrative Authentication Bypass
CVE-2013-0632CRITICALbajo ataquewebappswindows21 ago 2013
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RIESGO
abrir ↗
Exploit-DB
Samsung DVR Firmware 1.10 - Authentication Bypass
CVE-2013-3585—webappshardware21 ago 2013
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to
28RIESGO
abrir ↗
Exploit-DB
Samsung DVR Firmware 1.10 - Authentication Bypass
CVE-2013-3586—webappshardware21 ago 2013
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID v
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xibo - 'layout' HTML Injection
CVE-2013-4888—webappsphp21 ago 2013
Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xibo - Cross-Site Request Forgery
CVE-2013-4889—webappsphp21 ago 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Twilight CMS - DeWeS Web Server Directory Traversal
CVE-2013-4900—webappsphp21 ago 2013
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Graphite Web - Unsafe Pickle Handling (Metasploit)
CVE-2013-5093—remoteunix21 ago 2013
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python
50RIESGO
abrir ↗
Metasploit300
freeFTPd PASS Command Buffer Overflow
CVE-2013-10042CRITICAL20 ago 2013
freeFTPd <= 1.0.10 PASS Command Stack-Based Buffer Overflow
63RIESGO
abrir ↗
Metasploit600
Graphite Web Unsafe Pickle Handling
CVE-2013-5093—20 ago 2013
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java - 'storeImageArray()' Invalid Array Indexing (Metasploit)
CVE-2013-2465CRITICALbajo ataqueransomwareremotemultiple19 ago 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 U
100RIESGO
abrir ↗
Exploit-DB
IBM 1754 GCM 1.18.0.22011 - Remote Command Execution
CVE-2013-0526—remotehardware19 ago 2013
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avoce
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.07 - 'STOR' Remote Buffer Overflow
CVE-2013-4730—remotewindows19 ago 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.0.8 - '.m3u' Local Crash (PoC)
CVE-2013-6283—doswindows19 ago 2013
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
AlgoSec Firewall Analyzer - Cross-Site Scripting
CVE-2013-5092—remotehardware16 ago 2013
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attacke
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ultra Mini HTTPd - Remote Stack Buffer Overflow (Metasploit)
CVE-2013-5019—remotewindows15 ago 2013
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component Media Manager - Arbitrary File Upload (Metasploit)
CVE-2013-5576—remotephp15 ago 2013
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before
50RIESGO
abrir ↗
Exploit-DB
KCFinder 2.51 - Local File Disclosure
CVE-2014-1222—webappsphp15 ago 2013
Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authe
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Chasys Draw IES - Local Buffer Overflow (Metasploit)
CVE-2013-3928—localwindows15 ago 2013
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote atta
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DotNetNuke DNNArticle Module 10.0 - SQL Injection
CVE-2013-5117—webappsphp15 ago 2013
SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Open-FTPD 1.2 - Arbitrary File Upload (Metasploit)
CVE-2010-2620—remotewindows13 ago 2013
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP StorageWorks P4000 Virtual SAN Appliance - Login Buffer Overflow (Metasploit)
CVE-2013-2343—remotewindows13 ago 2013
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attacke
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP StorageWorks P4000 Virtual SAN Appliance - Login Buffer Overflow (Metasploit)
CVE-2012-3282—remotewindows13 ago 2013
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attacke
28RIESGO
abrir ↗
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (1)
CVE-2013-7349—webappsphp12 ago 2013
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPVID 1.2.3 - Multiple Vulnerabilities
CVE-2008-4157—webappsphp12 ago 2013
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (1)
CVE-2013-7368—webappsphp12 ago 2013
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
← anteriorpágina 1133 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.