Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.270 exploits
Metasploit300
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
CVE-2013-1017—22 may 2013
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir ↗
Metasploit300
Java JMX Server Insecure Endpoint Code Execution Scanner
CVE-2015-2342—22 may 2013
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir ↗
Metasploit300
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
CVE-2013-1017—22 may 2013
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir ↗
Metasploit600
Java JMX Server Insecure Configuration Java Code Execution
CVE-2015-2342—22 may 2013
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir ↗
Metasploit200
Novell Client 2 SP3 nicm.sys Local Privilege Escalation
CVE-2013-3956—22 may 2013
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RIESGO
abrir ↗
Metasploit200
Kimai v0.9.2 'db_restore.php' SQL Injection
CVE-2013-10033CRITICAL21 may 2013
Kimai 0.9.2 db_restore.php SQL Injection
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
CVE-2013-3660HIGHbajo ataquedoswindows21 may 2013
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir ↗
GitHub PoC★ 30
For the analysis of CVE-2013-2028
CVE-2013-2028—21 may 2013
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
CVE-2013-3661—doswindows21 may 2013
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
CVE-2013-3130—doswindows21 may 2013
20RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2013-2094HIGHbajo ataque20 may 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗
GitHub PoC★ 91
original cve-2013-2094 exploit and a rewritten version for educational purposes
CVE-2013-2094HIGHbajo ataque20 may 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Python RRDtool Module - Function Format String
CVE-2013-2131—remotemultiple18 may 2013
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attacker
28RIESGO
abrir ↗
Exploit-DB
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
CVE-2013-2028—doslinux17 may 2013
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mutiny 5 - Arbitrary File Upload (Metasploit)
CVE-2013-0136—remotelinux17 may 2013
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RIESGO
abrir ↗
Exploit-DB
Exponent CMS 2.2.0 Beta 3 - Multiple Vulnerabilities
CVE-2013-3294—webappsphp17 may 2013
Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execut
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin WP Cleanfix - Cross-Site Request Forgery
CVE-2013-2108—webappsphp16 may 2013
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Mail On Update - Cross-Site Request Forgery
CVE-2013-2107—webappsphp16 may 2013
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Serva 32 TFTP 2.1.0 - Buffer Overflow (Denial of Service) (PoC)
CVE-2013-0145—doswindows15 may 2013
Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash
23RIESGO
abrir ↗
Metasploit200
Windows EPATHOBJ::pprFlattenRec Local Privilege Escalation
CVE-2013-3660HIGHbajo ataque15 may 2013
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir ↗
GitHub PoC★ 10
feliam/CVE-2013-2730
CVE-2013-2730—15 may 2013
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attacke
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jojo CMS - 'search' Cross-Site Scripting
CVE-2013-3082—webappsphp15 may 2013
Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote att
23RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2013-2729HIGHbajo ataque15 may 2013
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attack
83RIESGO
abrir ↗
Metasploit300
Mutiny 5 Arbitrary File Read and Delete
CVE-2013-0136—15 may 2013
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RIESGO
abrir ↗
Metasploit600
VMware vCenter Chargeback Manager ImageUploadServlet Arbitrary File Upload
CVE-2013-3520—15 may 2013
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers t
50RIESGO
abrir ↗
Metasploit600
Mutiny 5 Arbitrary File Upload
CVE-2013-0136—15 may 2013
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Jojo CMS - 'x-forwarded-for' HTTP header SQL Injection
CVE-2013-3081—webappsphp15 may 2013
SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2
23RIESGO
abrir ↗
GitHub PoC★ 24
feliam/CVE-2013-2729
CVE-2013-2729HIGHbajo ataque15 may 2013
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attack
83RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ERS Viewer 2011 - '.ERS' File Handling Buffer Overflow (Metasploit)
CVE-2013-0726—localwindows14 may 2013
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 1
43RIESGO
abrir ↗
Exploit-DB
Linux Kernel < 3.8.x - open-time Capability 'file_ns_capable()' Local Privilege Escalation
CVE-2013-1959—locallinux14 may 2013
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_m
23RIESGO
abrir ↗
← anteriorpágina 1145 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.