Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.270 exploits
Exploit-DB✓ VexDay Proof
WPS Office - 'Wpsio.dll' Stack Buffer Overflow
CVE-2012-4886—doswindows01 may 2013
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to exec
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivotek IP Cameras - Multiple Vulnerabilities
CVE-2013-1598—webappshardware01 may 2013
A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to th
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivotek IP Cameras - Multiple Vulnerabilities
CVE-2013-1597—webappshardware01 may 2013
A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET requ
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivotek IP Cameras - Multiple Vulnerabilities
CVE-2013-1596—webappshardware01 may 2013
An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP pac
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivotek IP Cameras - Multiple Vulnerabilities
CVE-2013-1594—webappshardware01 may 2013
An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wire
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin W3 Total Cache - PHP Code Execution (Metasploit)
CVE-2013-2010—remotephp01 may 2013
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
CVE-2013-1600—webappshardware01 may 2013
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
CVE-2013-1599—webappshardware01 may 2013
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
CVE-2013-1603—webappshardware01 may 2013
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DC
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
CVE-2013-1602—webappshardware01 may 2013
An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP ses
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
CVE-2013-1601—webappshardware01 may 2013
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processin
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cisco Linksys E4200 - '/apply.cgi' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-2679—remotehardware27 abr 2013
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow rem
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! 3.0.3 - 'remember.php' PHP Object Injection
CVE-2013-3242—webappsphp26 abr 2013
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an o
23RIESGO
abrir ↗
Metasploit300
IBM SPSS SamplePower C1Tab ActiveX Heap Overflow
CVE-2012-5946—26 abr 2013
Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac
50RIESGO
abrir ↗
Metasploit600
phpMyAdmin Authenticated Remote Code Execution via preg_replace()
CVE-2013-3238—25 abr 2013
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMyAdmin 3.5.8/4.0.0-RC2 - Multiple Vulnerabilities
CVE-2013-3239—webappsphp25 abr 2013
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authentica
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMyAdmin 3.5.8/4.0.0-RC2 - Multiple Vulnerabilities
CVE-2013-3238—webappsphp25 abr 2013
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMyAdmin 3.5.8/4.0.0-RC2 - Multiple Vulnerabilities
CVE-2013-3241—webappsphp25 abr 2013
export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the co
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 (Windows) - Remote Buffer Overflow
CVE-2002-1549—remotewindows25 abr 2013
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Belkin F5D8236-4 Router - Cross-Site Request Forgery
CVE-2013-3083—remotehardware25 abr 2013
Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attac
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpMyAdmin 3.5.8/4.0.0-RC2 - Multiple Vulnerabilities
CVE-2013-3240—webappsphp25 abr 2013
Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated u
23RIESGO
abrir ↗
Exploit-DB
Hornbill Supportworks ITSM 1.0.0 - SQL Injection
CVE-2013-2594—webappsphp25 abr 2013
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote at
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GroundWork - 'monarch_scan.cgi' OS Command Injection (Metasploit)
CVE-2013-3502—remotelinux25 abr 2013
monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to ex
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin WP Super Cache - PHP Remote Code Execution
CVE-2013-2009—webappsphp24 abr 2013
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TP-Link TL-WR1043N Router - Cross-Site Request Forgery
CVE-2013-2645—remotehardware24 abr 2013
Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_12
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet - Reflection Type Confusion Remote Code Execution (Metasploit)
CVE-2013-2423LOWbajo ataqueremotemultiple23 abr 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and
95RIESGO
abrir ↗
Metasploit300
ERS Viewer 2011 ERS File Handling Buffer Overflow
CVE-2013-0726—23 abr 2013
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 1
43RIESGO
abrir ↗
Metasploit600
D-Link Devices Unauthenticated Remote Command Execution
CVE-2013-10050HIGH22 abr 2013
D-Link Devices tools_vct.xgi Authenticated RCE
41RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_civicrm 4.2.2 - Remote Code Injection
CVE-2009-4140—webappsphp22 abr 2013
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RIESGO
abrir ↗
Metasploit200
Tincd Post-Authentication Remote TCP Stack Buffer Overflow
CVE-2013-1428—22 abr 2013
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RIESGO
abrir ↗
← anteriorpágina 1147 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.