Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.192 exploits
Exploit-DB✓ VexDay Proof
VMware vCenter - Chargeback Manager ImageUploadServlet Arbitrary File Upload (Metasploit)
CVE-2013-3520—remotewindows23 jul 2013
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers t
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XnView 2.03 - '.pct' Buffer Overflow
CVE-2013-2577—doswindows23 jul 2013
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
28RIESGO
abrir ↗
Exploit-DB
Samsung PS50C7700 TV - Denial of Service
CVE-2013-4890—doshardware23 jul 2013
The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon cras
23RIESGO
abrir ↗
Exploit-DB
Microsoft DirectShow - Arbitrary Memory Overwrite (MS13-056)
CVE-2013-3174—doswindows23 jul 2013
DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection (Metasploit)
CVE-2013-2121—remotelinux23 jul 2013
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
CVE-2013-1017—remotewindows22 jul 2013
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.0.7 - Remote (Metasploit)
CVE-2013-4730—remotewindows22 jul 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP Managed Printing Administration - jobAcct Remote Command Execution (Metasploit)
CVE-2011-4166—remotewindows22 jul 2013
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Anchor CMS 0.9.1 - Persistent Cross-Site Scripting
CVE-2013-5099—webappsphp18 jul 2013
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote at
23RIESGO
abrir ↗
Exploit-DB
Microsoft Windows Movie Maker 2.1.4026.0 - '.wav' Crash (PoC)
CVE-2013-4858—doswindows18 jul 2013
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (applica
28RIESGO
abrir ↗
Exploit-DB
Xibo 1.2.2/1.4.1 - 'index.php?p' Directory Traversal
CVE-2013-5979—webappsphp18 jul 2013
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attacke
43RIESGO
abrir ↗
Exploit-DB
Microsoft Windows Movie Maker 2.1.4026.0 - '.wav' Crash (PoC)
CVE-2014-2671—doswindows18 jul 2013
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir ↗
Exploit-DB
Symantec Workspace Virtualization 6.4.1895.0 - Kernel Mode Privilege Escalation
CVE-2013-4679—localwindows18 jul 2013
Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows l
23RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2013-2596HIGHbajo ataque16 jul 2013
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain
71RIESGO
abrir ↗
GitHub PoC★ 5
CVE-2013-2596 exploit for android
CVE-2013-2596HIGHbajo ataque16 jul 2013
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain
71RIESGO
abrir ↗
Metasploit600
Oracle Endeca Server Remote Command Execution
CVE-2013-3763—16 jul 2013
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows rem
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BlazeDVD Pro Player 6.1 - Direct RET Local Stack Buffer Overflow
CVE-2006-6199—localwindows16 jul 2013
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Squid 3.3.5 - Denial of Service (PoC)
CVE-2013-4123—doslinux16 jul 2013
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Struts 2.2.3 - Multiple Open Redirections
CVE-2013-2248—remotemultiple16 jul 2013
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to
60RIESGO
abrir ↗
Exploit-DB
rpcbind - CALLIT procedure UDP Crash (PoC)
CVE-2013-1950—doslinux16 jul 2013
The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ReadyMedia - Remote Heap Buffer Overflow
CVE-2013-2739—remotewindows15 jul 2013
MiniDLNA has heap-based buffer overflow
23RIESGO
abrir ↗
Exploit-DB
McAfee ePO 4.6.6 - Multiple Vulnerabilities
CVE-2013-4882—webappswindows13 jul 2013
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (e
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
CVE-2013-0742—localwindows13 jul 2013
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
CVE-2013-3248—localwindows13 jul 2013
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wi
43RIESGO
abrir ↗
Exploit-DB
BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities
CVE-2013-4945—webappsasp13 jul 2013
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arb
23RIESGO
abrir ↗
Exploit-DB
McAfee ePO 4.6.6 - Multiple Vulnerabilities
CVE-2013-4883—webappswindows13 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extens
23RIESGO
abrir ↗
Exploit-DB
Tri-PLC Nano-10 r81 - Denial of Service
CVE-2013-2784—doshardware13 jul 2013
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bo
23RIESGO
abrir ↗
Exploit-DB
BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities
CVE-2013-4946—webappsasp13 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Pie Register - 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4954—webappsphp12 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before
23RIESGO
abrir ↗
Metasploit600
Linksys Devices pingstr Remote Command Injection
CVE-2013-3568—12 jul 2013
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentica
43RIESGO
abrir ↗
← anteriorpágina 1137 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.