Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.198exploits catalogados
37.770CVEs con explotación pública
24.695probados en laboratorio
81.198 exploits
Exploit-DB
OpenX 2.8.10 - Multiple Vulnerabilities
CVE-2013-7376—webappsphp05 jul 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote
23RIESGO
abrir ↗
Exploit-DB
Kasseler CMS 2 r1223 - Multiple Vulnerabilities
CVE-2013-3729—webappsphp05 jul 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hija
23RIESGO
abrir ↗
Metasploit300
D-Link Devices UPnP SOAP Command Execution
CVE-2014-8361CRITICALbajo ataque05 jul 2013
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Google Android - 'APK' code Remote Security Bypass
CVE-2013-4787—remoteandroid03 jul 2013
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Winamp 5.63 - Stack Buffer Overflow
CVE-2013-4694—doswindows02 jul 2013
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Intelligent Platform Management Interface - Information Disclosure
CVE-2013-4786—remotemultiple02 jul 2013
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4950—webappsphp02 jul 2013
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Exploit-DB
Winamp 5.63 - Invalid Pointer Dereference
CVE-2013-4695—doswindows02 jul 2013
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4949—webappsphp02 jul 2013
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code b
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4948—webappsphp02 jul 2013
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Metasploit600
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
CVE-2013-2251CRITICALbajo ataque02 jul 2013
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - 'EPATHOBJ::pprFlattenRec' Local Privilege Escalation (Metasploit)
CVE-2013-3130—localwindows02 jul 2013
20RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - 'EPATHOBJ::pprFlattenRec' Local Privilege Escalation (Metasploit)
CVE-2013-3660HIGHbajo ataquelocalwindows02 jul 2013
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer - Denial of Service
CVE-2013-3299—dosmultiple02 jul 2013
RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Category Grid View Gallery - 'ID' Cross-Site Scripting
CVE-2013-4117—webappsphp02 jul 2013
Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - 'EPATHOBJ::pprFlattenRec' Local Privilege Escalation (Metasploit)
CVE-2013-3661—localwindows02 jul 2013
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft PowerPoint 2007 - Crash (PoC)
CVE-2014-2671—doswindows01 jul 2013
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir ↗
Exploit-DB
Fortigate Firewalls - Cross-Site Request Forgery
CVE-2013-1414—webappshardware01 jul 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.
23RIESGO
abrir ↗
Exploit-DB
Static HTTP Server 1.0 - Local Overflow (SEH)
CVE-2013-4743—localwindows01 jul 2013
Static HTTP Server 1.0 has a Local Overflow
23RIESGO
abrir ↗
Exploit-DB
GLPI 0.83.9 - 'Unserialize()' Remote Code Execution
CVE-2013-2225—webappsphp01 jul 2013
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _pr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
libvirt - 'virConnectListAllInterfaces' Method Denial of Service
CVE-2013-2218—doslinux01 jul 2013
Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet - ProviderSkeleton Insecure Invoke Method (Metasploit)
CVE-2013-2460—remotemultiple01 jul 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and
60RIESGO
abrir ↗
Exploit-DB
PCMan FTP Server 2.0 - Remote Buffer Overflow
CVE-2013-4730—remotewindows30 jun 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Xorbin Analog Flash Clock - 'widgetUrl' Cross-Site Scripting
CVE-2013-4692—webappsphp30 jun 2013
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
YardRadius - Multiple Local Format String Vulnerabilities
CVE-2013-4147—localwindows30 jun 2013
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attacker
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Xorbin Digital Flash Clock - 'widgetUrl' Cross-Site Scripting
CVE-2013-4692—webappsphp30 jun 2013
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
23RIESGO
abrir ↗
Metasploit600
Nodejs js-yaml load() Code Execution
CVE-2013-4660—28 jun 2013
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, whic
43RIESGO
abrir ↗
Metasploit300
HP StorageWorks P4000 Virtual SAN Appliance Login Buffer Overflow
CVE-2013-2343—28 jun 2013
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attacke
50RIESGO
abrir ↗
Metasploit600
Horde Framework Unserialize PHP Code Execution
CVE-2014-1691—27 jun 2013
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to c
50RIESGO
abrir ↗
Metasploit300
MS13-059 Microsoft Internet Explorer CFlatMarkupPointer Use-After-Free
CVE-2013-3184—27 jun 2013
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
50RIESGO
abrir ↗
← anteriorpágina 1139 / 2707siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.