Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.270 exploits
Exploit-DB✓ VexDay Proof
phpMyAdmin - 'tbl_gis_visualization.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-1937—webappsphp09 abr 2013
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZAPms 1.41 - SQL Injection
CVE-2013-3050—webappsphp09 abr 2013
SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Metasploit600
MiniWeb (Build 300) Arbitrary File Upload
CVE-2013-10047CRITICAL09 abr 2013
MiniWeb <= Build 300 Arbitrary File Upload
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Traffic Analyzer - 'aoid' Cross-Site Scripting
CVE-2013-3526—webappsphp09 abr 2013
Cross-site scripting (XSS) vulnerability in js/ta_loaded.js.php in the Traffic Analyzer plugin, possibly 3.3.2 and earli
43RIESGO
abrir ↗
Exploit-DB
Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities
CVE-2013-2641—webappslinux08 abr 2013
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MongoDB 2.2.3 - nativeHelper.apply Remote Code Execution
CVE-2013-1892—remotelinux08 abr 2013
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMo
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MongoDB - nativeHelper.apply Remote Code Execution (Metasploit)
CVE-2013-1892—remotelinux08 abr 2013
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMo
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell ZENworks Configuration Management 10 SP3/11 SP2 - Remote Execution (Metasploit)
CVE-2013-1080—remotemultiple08 abr 2013
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Groovy Media Player 3.2.0 - '.mp3' Buffer Overflow
CVE-2013-2760—doswindows08 abr 2013
Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m
23RIESGO
abrir ↗
Exploit-DB
WHMCompleteSolution (WHMCS) Group Pay Plugin 1.5 - 'grouppay.php?hash' SQL Injection
CVE-2013-3536—webappsphp08 abr 2013
SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and ea
23RIESGO
abrir ↗
Exploit-DB
Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities
CVE-2013-2643—webappslinux08 abr 2013
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inj
23RIESGO
abrir ↗
Exploit-DB
Sophos Web Protection Appliance 3.7.8.1 - Multiple Vulnerabilities
CVE-2013-2642—webappslinux08 abr 2013
Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters i
23RIESGO
abrir ↗
Exploit-DB
Belkin Wemo - Arbitrary Firmware Upload
CVE-2013-2748—webappshardware08 abr 2013
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
28RIESGO
abrir ↗
Exploit-DB
Vanilla Forums 2-0-18-4 - SQL Injection
CVE-2013-3527—webappsphp08 abr 2013
Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OTRS 3.x - FAQ Module Persistent Cross-Site Scripting
CVE-2013-2637—webappsmultiple08 abr 2013
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Subversion 1.6.x - 'mod_dav_svn/lock.c' Remote Denial of Service
CVE-2013-1847—doslinux05 abr 2013
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote atta
35RIESGO
abrir ↗
Metasploit600
ABB MicroSCADA wserver.exe Remote Code Execution
CVE-2019-5620—05 abr 2013
ABB MicroSCADA Pro SYS600 Missing Authentication for Critical Function
40RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/checklogin.php?Username' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/admin_index.php?q' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/linktick.php?site' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/user_add_save.php?email' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/edit_user_save.php' Multiple SQL Injections
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/reset_password_save.php' Multiple SQL Injections
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/reset_password.php' Multiple SQL Injections
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Subversion - Remote Denial of Service
CVE-2013-1884—doslinux05 abr 2013
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial o
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Zimbra - 'aspell.php' Cross-Site Scripting
CVE-2013-1938—webappsphp05 abr 2013
Zimbra 2013 has XSS in aspell.php
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/delete_user.php?id' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/edit_user.php?id' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/router.php?BasicLogin' Cookie SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP Address Book - '/addressbook/register/traffic.php?var' SQL Injection
CVE-2013-0135—webappsphp05 abr 2013
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
← anteriorpágina 1149 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.