Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.269exploits catalogados
37.817CVEs con explotación pública
24.695probados en laboratorio
81.269 exploits
Metasploit300
PCMAN FTP Server Post-Authentication STOR Command Stack Buffer Overflow
CVE-2013-4730—27 jun 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗
Metasploit300
MS13-059 Microsoft Internet Explorer CFlatMarkupPointer Use-After-Free
CVE-2013-3184—27 jun 2013
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle VM VirtualBox 4.0 - 'tracepath' Local Denial of Service
CVE-2013-3792—dosmultiple26 jun 2013
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.18, 4.0
23RIESGO
abrir ↗
Metasploit600
InstantCMS 1.6 Remote PHP Code Execution
CVE-2013-10051CRITICAL26 jun 2013
InstantCMS <= 1.6 Remote PHP Code Execution
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 9 - Address Space Manipulation Privilege Escalation (Metasploit)
CVE-2013-2171—localfreebsd26 jun 2013
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell Client 2 SP3 - 'nicm.sys' Local Privilege Escalation (Metasploit)
CVE-2013-3956—localwindows_x8626 jun 2013
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Xaraya - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-3639—webappsphp26 jun 2013
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbi
23RIESGO
abrir ↗
Metasploit300
Firefox onreadystatechange Event DocumentViewerImpl Use After Free
CVE-2013-1690HIGHbajo ataque25 jun 2013
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MoinMoin - twikidraw Action Traversal Arbitrary File Upload (Metasploit)
CVE-2012-6495—remotelinux24 jun 2013
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anyw
28RIESGO
abrir ↗
Exploit-DB
Elemata CMS RC3.0 - 'global.php?id' SQL Injection
CVE-2013-4952—webappsphp24 jun 2013
SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MoinMoin - twikidraw Action Traversal Arbitrary File Upload (Metasploit)
CVE-2012-6081—remotelinux24 jun 2013
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpEventCalendar 0.2.3 - Multiple Vulnerabilities
CVE-2007-3519—webappsphp24 jun 2013
SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB
Linksys X3000 1.0.03 build 001 - Multiple Vulnerabilities
CVE-2013-3307HIGHwebappshardware24 jun 2013
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj
53RIESGO
abrir ↗
Exploit-DB
Alienvault Open Source SIEM (OSSIM) 4.1 - Multiple SQL Injection Vulnerabilities
CVE-2013-5321—webappsphp24 jun 2013
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
HP System Management Homepage - JustGetSNMPQueue Command Injection (Metasploit)
CVE-2013-3576—remotewindows24 jun 2013
ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands vi
50RIESGO
abrir ↗
Exploit-DB
Novell Client 4.91 SP4 - 'nwfs.sys' Local Privilege Escalation (Metasploit)
CVE-2008-3158—localwindows24 jun 2013
Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possi
38RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Top Games Script 1.2 - 'play.php?gid' SQL Injection
CVE-2013-4953—webappsphp24 jun 2013
SQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Metasploit300
MediaCoder .M3U Buffer Overflow
CVE-2017-8869—24 jun 2013
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir ↗
Exploit-DB
GLPI 0.83.8 - Multiple Vulnerabilities
CVE-2013-2226—webappsphp21 jun 2013
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Exploit-DB
GLPI 0.83.8 - Multiple Vulnerabilities
CVE-2013-2227—webappsphp21 jun 2013
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FreeBSD 9.0 < 9.1 - 'mmap/ptrace' Local Privilege Escalation
CVE-2013-2171—localfreebsd21 jun 2013
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RIESGO
abrir ↗
Metasploit300
IPMI 2.0 RAKP Remote SHA1 Password Hash Retrieval
CVE-2013-4786—20 jun 2013
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir ↗
Metasploit300
IPMI 2.0 Cipher Zero Authentication Bypass Scanner
CVE-2013-4782—20 jun 2013
The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands b
23RIESGO
abrir ↗
Metasploit300
Canon Wireless Printer Denial Of Service
CVE-2013-4615—18 jun 2013
The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause
23RIESGO
abrir ↗
Metasploit500
FreeBSD 9 Address Space Manipulation Privilege Escalation
CVE-2013-2171—18 jun 2013
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RIESGO
abrir ↗
Metasploit300
Canon Printer Wireless Configuration Disclosure
CVE-2013-4614—18 jun 2013
English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX9
18RIESGO
abrir ↗
GitHub PoC
tarunyadav/fix-cve-2013-2094
CVE-2013-2094HIGHbajo ataque18 jun 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗
Metasploit500
Java Applet ProviderSkeleton Insecure Invoke Method
CVE-2013-2460—18 jun 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and
60RIESGO
abrir ↗
Metasploit600
Havalite CMS Arbitary File Upload Vulnerability
CVE-2013-10055CRITICAL17 jun 2013
Havalite CMS Arbitary File Upload RCE
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Winamp 5.12 - '.m3u' Local Stack Buffer Overflow
CVE-2006-0720—localwindows17 jun 2013
Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service
28RIESGO
abrir ↗
← anteriorpágina 1141 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.