Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.270 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component com_civicrm 4.2.2 - Remote Code Injection
CVE-2011-4275—webappsphp22 abr 2013
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
D-Link DIR-865L - Cross-Site Request Forgery
CVE-2013-3095—remotehardware19 abr 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b
23RIESGO
abrir ↗
Exploit-DB
Java Web Start Launcher ActiveX Control - Memory Corruption
CVE-2013-2419—doswindows18 abr 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 U
28RIESGO
abrir ↗
Exploit-DB
KrisonAV CMS 3.0.1 - Multiple Vulnerabilities
CVE-2013-2713—webappsphp18 abr 2013
Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers
23RIESGO
abrir ↗
Exploit-DB
KrisonAV CMS 3.0.1 - Multiple Vulnerabilities
CVE-2013-2712—webappsphp18 abr 2013
Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attacker
23RIESGO
abrir ↗
Exploit-DB
Oracle WebCenter Sites Satellite Server - HTTP Header Injection
CVE-2013-1509—webappswindows18 abr 2013
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.0, and 11.
23RIESGO
abrir ↗
Exploit-DB
Java Web Start Launcher ActiveX Control - Memory Corruption
CVE-2013-2416—doswindows18 abr 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allo
23RIESGO
abrir ↗
Metasploit600
WordPress W3 Total Cache PHP Code Execution
CVE-2013-2010—17 abr 2013
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RIESGO
abrir ↗
Metasploit600
Oracle WebCenter Content CheckOutAndOpen.dll ActiveX Remote Code Execution
CVE-2013-1559—16 abr 2013
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.
50RIESGO
abrir ↗
Exploit-DB
ZPanel - 'templateparser.class.php' Crafted Template Remote Command Execution
CVE-2013-2097—webappsphp16 abr 2013
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pwstore - Denial of Service
CVE-2013-5657—doswindows16 abr 2013
AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 3.2.1 - Tracing Multiple Local Denial of Service Vulnerabilities
CVE-2013-3301—doslinux15 abr 2013
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer
23RIESGO
abrir ↗
Exploit-DB
CMSLogik 1.2.1 - Multiple Vulnerabilities
CVE-2013-3535—webappsphp15 abr 2013
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpVms Virtual Airline Administration 2.1.934/2.1.935 - SQL Injection
CVE-2013-3524—webappsphp15 abr 2013
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remot
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Todoo Forum 2.0 - 'todooforum.php' Multiple SQL Injections
CVE-2013-3537—webappsphp14 abr 2013
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
GitHub PoC★ 1
Discover uPNP devices vulnerable to CVE-2013-0229 / CVE-2013-0230 / CVE-2012-5958 / CVE-2012-5959
CVE-2012-5958—14 abr 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Todoo Forum 2.0 - 'todooforum.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-3538—webappsphp14 abr 2013
Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to injec
23RIESGO
abrir ↗
GitHub PoC★ 1
Discover uPNP devices vulnerable to CVE-2013-0229 / CVE-2013-0230 / CVE-2012-5958 / CVE-2012-5959
CVE-2013-0229—14 abr 2013
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Simple HRM System 2.3 - Multiple Vulnerabilities
CVE-2013-2498—webappsphp12 abr 2013
SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earli
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KNet Web Server 1.04b - Stack Corruption Buffer Overflow
CVE-2005-0575—remotewindows12 abr 2013
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Allied Telesyn TFTP (AT-TFTP) Server/Daemon 2.0 - Stack Buffer Overflow (Denial of Service) (PoC)
CVE-2006-6184—doswindows12 abr 2013
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nagios Remote Plugin Executor - Arbitrary Command Execution (Metasploit)
CVE-2013-1362—remotelinux12 abr 2013
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote att
50RIESGO
abrir ↗
Exploit-DB
ircd-hybrid 8.0.5 - Denial of Service
CVE-2013-0238—doslinux12 abr 2013
The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allo
23RIESGO
abrir ↗
Metasploit600
Ruby on Rails Known Secret Session Cookie Remote Code Execution
CVE-2013-0156—11 abr 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Request Tracker - 'ShowPending' SQL Injection
CVE-2013-3525—webappsphp11 abr 2013
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Spider Video Player - 'theme' SQL Injection
CVE-2013-3532—webappsphp11 abr 2013
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe ColdFusion APSB13-03 - Remote Multiple Vulnerabilities (Metasploit)
CVE-2013-0625CRITICALbajo ataqueremotemultiple10 abr 2013
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authenticat
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe ColdFusion APSB13-03 - Remote Multiple Vulnerabilities (Metasploit)
CVE-2013-0629HIGHbajo ataqueremotemultiple10 abr 2013
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted dir
83RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Spiffy XSPF Player - 'playlist_id' SQL Injection
CVE-2013-3530—webappsphp10 abr 2013
SQL injection vulnerability in playlist.php in the Spiffy XSPF Player plugin 0.1 for WordPress allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Adobe ColdFusion APSB13-03 - Remote Multiple Vulnerabilities (Metasploit)
CVE-2013-0632CRITICALbajo ataqueremotemultiple10 abr 2013
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RIESGO
abrir ↗
← anteriorpágina 1148 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.