Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Exploit-DB✓ VexDay Proof
PHPVID 1.2.3 - Multiple Vulnerabilities
CVE-2008-2335—webappsphp12 ago 2013
Cross-site scripting (XSS) vulnerability in search_results.php in Vastal I-Tech phpVID 1.1 and 1.2 allows remote attacke
23RIESGO
abrir ↗
Metasploit500
Java storeImageArray() Invalid Array Indexing Vulnerability
CVE-2013-2465CRITICALbajo ataqueransomware12 ago 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 U
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ruby on Rails - Known Secret Session Cookie Remote Code Execution (Metasploit)
CVE-2013-0156—remotemultiple12 ago 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Hms Testimonials 2.0.10 - Multiple Vulnerabilities
CVE-2013-4240—webappsphp12 ago 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress al
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Squash - YAML Code Execution (Metasploit)
CVE-2013-5036—remotemultiple12 ago 2013
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter t
50RIESGO
abrir ↗
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (1)
CVE-2013-5640—webappsphp12 ago 2013
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPVID 1.2.3 - Multiple Vulnerabilities
CVE-2013-5312—webappsphp12 ago 2013
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Hms Testimonials 2.0.10 - Multiple Vulnerabilities
CVE-2013-4241—webappsphp12 ago 2013
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow rem
23RIESGO
abrir ↗
Exploit-DB
Joomla! Component redSHOP 1.2 - SQL Injection
CVE-2010-2694—webappsphp12 ago 2013
SQL injection vulnerability in the redSHOP Component (com_redshop) 1.0 for Joomla! allows remote attackers to execute ar
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenX - Backdoor PHP Code Execution (Metasploit)
CVE-2013-4211—remotephp12 ago 2013
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, wh
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPVID 1.2.3 - Multiple Vulnerabilities
CVE-2013-5311—webappsphp12 ago 2013
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BigTree CMS 4.0 RC2 - Multiple Vulnerabilities
CVE-2013-4879—webappsphp08 ago 2013
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BigTree CMS 4.0 RC2 - Multiple Vulnerabilities
CVE-2013-4881—webappsphp08 ago 2013
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlie
23RIESGO
abrir ↗
Exploit-DB
PHPFox 3.6.0 (build3) - Multiple SQL Injections
CVE-2013-5121—webappsphp08 ago 2013
SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Metasploit300
Adobe Reader ToolButton Use After Free
CVE-2013-3346HIGHbajo ataque08 ago 2013
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitr
100RIESGO
abrir ↗
Metasploit300
Adobe Reader ToolButton Use After Free
CVE-2013-3346HIGHbajo ataque08 ago 2013
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitr
100RIESGO
abrir ↗
Metasploit500
Adobe ColdFusion RDS Authentication Bypass
CVE-2013-0632CRITICALbajo ataque08 ago 2013
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox - onreadystatechange Event DocumentViewerImpl Use-After-Free (Metasploit)
CVE-2013-1690HIGHbajo ataqueremotewindows08 ago 2013
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BigTree CMS 4.0 RC2 - Multiple Vulnerabilities
CVE-2013-4880—webappsphp08 ago 2013
Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 an
23RIESGO
abrir ↗
Exploit-DB
PHPFox 3.6.0 (build3) - Multiple SQL Injections
CVE-2013-5120—webappsphp08 ago 2013
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Kwok Information Server - Multiple SQL Injections
CVE-2013-5028—webappscgi07 ago 2013
SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authen
23RIESGO
abrir ↗
GitHub PoC★ 2
Do you own security hotfix with Deviare hooking
CVE-2010-3971—07 ago 2013
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir ↗
Metasploit600
OpenX Backdoor PHP Code Execution
CVE-2013-4211—07 ago 2013
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, wh
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hikvision IP Cameras 4.1.0 b130111 - Multiple Vulnerabilities
CVE-2013-4976—webappshardware07 ago 2013
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
(Gabriel's FTP Server) Open & Compact FTP Server 1.2 - Authentication Bypass / Directory Traversal SAM Retrieval
CVE-2010-2620—remotewindows07 ago 2013
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST
43RIESGO
abrir ↗
Exploit-DB
HP Data Protector - Remote Command Execution
CVE-2011-0923—remotewindows07 ago 2013
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hikvision IP Cameras 4.1.0 b130111 - Multiple Vulnerabilities
CVE-2013-4977—webappshardware07 ago 2013
Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), a
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Hikvision IP Cameras 4.1.0 b130111 - Multiple Vulnerabilities
CVE-2013-4975—webappshardware07 ago 2013
Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
McAfee SuperScan 4.0 - Cross-Site Scripting
CVE-2013-4884—webappswindows07 ago 2013
Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Metasploit600
Firefox 5.0 - 15.0.1 __exposedProps__ XCS Code Execution
CVE-2012-3993—06 ago 2013
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbi
50RIESGO
abrir ↗
← anteriorpágina 1134 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.