Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
81.270 exploits
Metasploit300
Portable UPnP SDK unique_service_name() Remote Code Execution
CVE-2012-5958—29 ene 2013
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗
GitHub PoC★ 2
heroku/heroku-CVE-2013-0333
CVE-2013-0333—29 ene 2013
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0333—remotemultiple29 ene 2013
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RIESGO
abrir ↗
Exploit-DB
Microsoft Internet Explorer 8/9 - Steal Any Cookie
CVE-2013-1451—webappswindows28 ene 2013
Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DataLife Engine 9.7 - 'preview.php' PHP Code Injection
CVE-2013-1412—webappsphp28 ene 2013
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RIESGO
abrir ↗
Metasploit600
Ruby on Rails JSON Processor YAML Deserialization Code Execution
CVE-2013-0333—28 ene 2013
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DataLife Engine 9.7 - 'preview.php' PHP Code Injection
CVE-2013-7387—webappsphp28 ene 2013
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v
23RIESGO
abrir ↗
Metasploit600
DataLife Engine preview.php PHP Code Injection
CVE-2013-1412—28 ene 2013
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RIESGO
abrir ↗
Metasploit300
Ruby on Rails Devise Authentication Password Reset
CVE-2013-0233—28 ene 2013
Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certa
23RIESGO
abrir ↗
Exploit-DB
ImageCMS 4.0.0b - Multiple Vulnerabilities
CVE-2012-6290—webappsphp25 ene 2013
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Novell eDirectory 8 - Remote Buffer Overflow (Metasploit)
CVE-2012-0432—remotemultiple24 ene 2013
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZoneMinder Video Server - packageControl Command Execution (Metasploit)
CVE-2013-0232—remoteunix24 ene 2013
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitra
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet - AverageRangeStatisticImpl Remote Code Execution (Metasploit)
CVE-2012-5076CRITICALbajo ataqueremotejava24 ene 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SonicWALL Gms 6 - Arbitrary File Upload (Metasploit)
CVE-2013-1359—remotemultiple24 ene 2013
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ZoneMinder Video Server - packageControl Command Execution (Metasploit)
CVE-2013-0332—remoteunix24 ene 2013
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin WP-Table Reloaded - 'id' Cross-Site Scripting
CVE-2013-1463—webappsphp24 ene 2013
Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet - Method Handle Remote Code Execution (Metasploit)
CVE-2012-5088—remotemultiple24 ene 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
gpEasy CMS - 'section' Cross-Site Scripting
CVE-2013-0807—webappsphp23 ene 2013
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DigiLIBE - Execution-After-Redirect Information Disclosure
CVE-2013-1402—webappsphp22 ene 2013
DigiLIBE 3.4 and possibly other versions sends a redirect but does not exit, which allows remote attackers to obtain sen
23RIESGO
abrir ↗
Metasploit600
ZoneMinder Video Server packageControl Command Execution
CVE-2013-0232—22 ene 2013
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitra
50RIESGO
abrir ↗
Metasploit300
GE Proficy Cimplicity WebView substitute.bcl Directory Traversal
CVE-2013-0653—22 ene 2013
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Perforce P4Web - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-1410—webappsjsp22 ene 2013
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU Coreutils 'sort' Text Utility - Local Buffer Overflow
CVE-2013-0221—locallinux21 ene 2013
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segment
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
F5 Networks BIG-IP - XML External Entity Injection
CVE-2012-2997—remotehardware21 ene 2013
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 1
23RIESGO
abrir ↗
Metasploit600
Java Applet JMX Remote Code Execution
CVE-2013-0431MEDIUMbajo ataqueransomware19 ene 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and Ope
100RIESGO
abrir ↗
Metasploit300
Polycom Command Shell Authorization Bypass
CVE-2012-6610—18 ene 2013
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗
Metasploit600
EMC AlphaStor Device Manager Opcode 0x75 Command Injection
CVE-2013-0928—18 ene 2013
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir ↗
Metasploit300
Linksys WRT54GL Remote Command Execution
CVE-2023-31742HIGH18 ene 2013
There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attack
36RIESGO
abrir ↗
Metasploit300
Cool PDF Image Stream Buffer Overflow
CVE-2012-4914—18 ene 2013
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RIESGO
abrir ↗
Metasploit0
Linksys WRT54GL apply.cgi Command Execution
CVE-2005-2799—18 ene 2013
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RIESGO
abrir ↗
← anteriorpágina 1156 / 2709siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.