Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Exploit-DB✓ VexDay Proof
HP Data Protector - CMD Install Service (Metasploit)
CVE-2011-0922—remotewindows02 ago 2013
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cotonti 0.9.13 - SQL Injection
CVE-2013-4789—webappsphp02 ago 2013
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
CVE-2013-4864—webappshardware02 ago 2013
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
CVE-2013-2580—webappshardware02 ago 2013
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ginkgo CMS - 'index.php?rang' SQL Injection
CVE-2013-5318—webappsphp02 ago 2013
SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang par
23RIESGO
abrir ↗
Exploit-DB
Linux Kernel 3.7.6 (RedHat x86/x64) - 'MSR' Driver Privilege Escalation
CVE-2013-0268—locallinux02 ago 2013
The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended ca
23RIESGO
abrir ↗
Metasploit600
Joomla Media Manager File Upload Vulnerability
CVE-2013-5576—01 ago 2013
administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SilverStripe CMS - 'MemberLoginForm.php' Information Disclosure
CVE-2013-2653—webappsphp01 ago 2013
security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Plone - 'in_portal.py' < 4.1.3 Session Hijacking
CVE-2013-4200—webappspython31 jul 2013
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jahia xCM - '/administration/' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4624—webappsphp31 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jahia xCM - '/engines/manager.jsp?site' Cross-Site Scripting
CVE-2013-4624—webappsphp31 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to injec
23RIESGO
abrir ↗
Metasploit0
HP SiteScope Remote Code Execution
CVE-2013-2367—29 jul 2013
Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execu
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Client 2 SP3 - 'nicm.sys 3.1.11.0' Local Privilege Escalation
CVE-2013-3956—localwindows29 jul 2013
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RIESGO
abrir ↗
Exploit-DB
TRENDnet TEW-812DRU - Cross-Site Request Forgery/Command Injection Root
CVE-2013-3365—webappshardware28 jul 2013
TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in t
23RIESGO
abrir ↗
Exploit-DB
TRENDnet TEW-812DRU - Cross-Site Request Forgery/Command Injection Root
CVE-2013-3098—webappshardware28 jul 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 al
23RIESGO
abrir ↗
Exploit-DB
Galil-RIO Modbus - Denial of Service
CVE-2013-0699—doshardware27 jul 2013
The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeate
23RIESGO
abrir ↗
Metasploit300
HP LoadRunner magentproc.exe Overflow
CVE-2013-4800—27 jul 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RIESGO
abrir ↗
Exploit-DB
ASUS RT-AC66U - 'acsd' Remote Command Execution
CVE-2013-4659—remotelinux_mips27 jul 2013
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. T
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)
CVE-2013-2251CRITICALbajo ataqueremotemultiple27 jul 2013
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.1.0.x - Multiple Vulnerabilities
CVE-2013-1616—webappsphp27 jul 2013
The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbit
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
xmonad XMonad.Hooks.DynamicLog Module - Multiple Remote Command Injection Vulnerabilities
CVE-2013-1436—remotelinux26 jul 2013
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands
23RIESGO
abrir ↗
Metasploit300
Chasys Draw IES Buffer Overflow
CVE-2013-3928—26 jul 2013
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote atta
50RIESGO
abrir ↗
Metasploit300
Cogent DataHub HTTP Server Buffer Overflow
CVE-2013-0680—26 jul 2013
Stack-based buffer overflow in the web server in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub befor
23RIESGO
abrir ↗
Metasploit600
PineApp Mail-SeCure test_li_connection.php Arbitrary Command Execution
CVE-2013-6829—26 jul 2013
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacha
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Magnolia CMS - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4759—webappsphp24 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 fo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Duplicator - Cross-Site Scripting
CVE-2013-4625—webappsphp24 jul 2013
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPr
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FOSCAM IP-Cameras - Improper Access Restrictions
CVE-2013-2574—webappshardware24 jul 2013
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /lo
28RIESGO
abrir ↗
Metasploit300
HP LoadRunner lrFileIOService ActiveX Remote Code Execution
CVE-2013-2370—24 jul 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RIESGO
abrir ↗
Metasploit300
HP LoadRunner lrFileIOService ActiveX WriteFileString Remote Code Execution
CVE-2013-4798—24 jul 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Artweaver 3.1.5 - '.awd' Buffer Overflow
CVE-2013-2576—doswindows23 jul 2013
Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly exec
23RIESGO
abrir ↗
← anteriorpágina 1136 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.