Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.270 exploits
Exploit-DB✓ VexDay Proof
Atmail WebMail - 'INBOX.Trash?mailId' Reflected Cross-Site Scripting
CVE-2013-6229—webappsphp25 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Atmail WebMail - 'searchResultsTab5?filter' Reflected Cross-Site Scripting
CVE-2013-6229—webappsphp25 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KingView - Log File Parsing Buffer Overflow (Metasploit)
CVE-2012-4711—remotewindows25 mar 2013
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
vBulletin 5.0.0 Beta 11 < 5.0.0 Beta 28 - SQL Injection
CVE-2013-3522—webappsphp25 mar 2013
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Atmail WebMail - Message Attachment File Name Reflected Cross-Site Scripting
CVE-2013-6229—webappsphp25 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Metasploit300
MongoDB nativeHelper.apply Remote Code Execution
CVE-2013-1892—24 mar 2013
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMo
50RIESGO
abrir ↗
Metasploit300
vBulletin Password Collector via nodeid SQL Injection
CVE-2013-3522—24 mar 2013
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RIESGO
abrir ↗
Metasploit500
Novell ZENworks Configuration Management Remote Execution
CVE-2013-1080—22 mar 2013
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenCart 1.5.5.1 - 'FileManager.php' Directory Traversal Arbitrary File Access
CVE-2013-1891—webappsphp22 mar 2013
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache Struts - 'ParametersInterceptor' Remote Code Execution (Metasploit)
CVE-2011-3923—remotemultiple22 mar 2013
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RIESGO
abrir ↗
Exploit-DB
GnuTLS libgnutls - Double-Free Certificate List Parsing Remote Denial of Service
CVE-2012-1663—doslinux22 mar 2013
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (app
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Cool PDF Image Stream - Remote Buffer Overflow (Metasploit)
CVE-2012-4914—remotewindows22 mar 2013
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RIESGO
abrir ↗
Exploit-DB
Verizon Fios Router MI424WR-GEN3I - Cross-Site Request Forgery
CVE-2013-0126—webappshardware19 mar 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I rout
23RIESGO
abrir ↗
Exploit-DB
ViewGit 0.0.6 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-2294—webappsphp19 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbi
23RIESGO
abrir ↗
Metasploit300
Sysax Multi-Server 6.10 SSHD Key Exchange Denial of Service
CVE-2013-10065HIGH17 mar 2013
Sysax Multi-Server <= 6.10 SSHD Key Exchange DoS
36RIESGO
abrir ↗
Exploit-DB
WordPress Plugin LeagueManager 3.8 - SQL Injection
CVE-2013-1852—webappsphp15 mar 2013
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RIESGO
abrir ↗
Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
CVE-2013-3430—webappsjsp15 mar 2013
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive,
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1645—webappsjava15 mar 2013
Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev
23RIESGO
abrir ↗
Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
CVE-2013-3431—webappsjsp15 mar 2013
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages,
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1649—webappsjava15 mar 2013
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithm
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1650—webappsjava15 mar 2013
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "othe
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1647—webappsjava15 mar 2013
Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 befo
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1646—webappsjava15 mar 2013
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1651—webappsjava15 mar 2013
OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509
23RIESGO
abrir ↗
Exploit-DB
Open-Xchange Server 6 - Multiple Vulnerabilities
CVE-2013-1648—webappsjava15 mar 2013
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does
23RIESGO
abrir ↗
Exploit-DB
Cisco Video Surveillance Operations Manager 6.3.2 - Multiple Vulnerabilities
CVE-2013-3429—webappsjsp15 mar 2013
Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attacke
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Honeywell HSC Remote Deployer - ActiveX Remote Code Execution (Metasploit)
CVE-2013-0108—remotewindows13 mar 2013
An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R
43RIESGO
abrir ↗
Exploit-DB
Linux Kernel - 'SCTP_GET_ASSOC_STATS()' Stack Buffer Overflow (PoC)
CVE-2013-1828—doslinux13 mar 2013
The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size
23RIESGO
abrir ↗
Metasploit600
Novell Zenworks Mobile Managment MDM.php Local File Inclusion Vulnerability
CVE-2013-1081—13 mar 2013
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RIESGO
abrir ↗
Exploit-DB
Apache Rave 0.11 < 0.20 - User Information Disclosure
CVE-2013-1814—webappsmultiple13 mar 2013
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RIESGO
abrir ↗
← anteriorpágina 1151 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.