Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.366exploits catalogados
37.872CVEs con explotación pública
24.695probados en laboratorio
81.366 exploits
Metasploit300
Cool PDF Image Stream Buffer Overflow
CVE-2012-4914—18 ene 2013
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RIESGO
abrir ↗
Exploit-DB
SonicWALL GMS/VIEWPOINT 6.x Analyzer 7.x - Remote Command Execution
CVE-2013-1359—webappsmultiple18 ene 2013
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RIESGO
abrir ↗
Exploit-DB
SonicWALL GMS/Viewpoint/Analyzer - Authentication Bypass
CVE-2013-1360—webappsmultiple18 ene 2013
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache OFBiz 10.4.x - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-0177—remotemultiple18 ene 2013
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business
28RIESGO
abrir ↗
Exploit-DB
Linksys WRT54GL Firmware 4.30.15 build 2 - Multiple Vulnerabilities
CVE-2013-2679—webappshardware18 ene 2013
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow rem
28RIESGO
abrir ↗
Metasploit600
PHP-Charts v1.0 PHP Code Execution Vulnerability
CVE-2013-10070CRITICAL16 ene 2013
PHP-Charts v1.0 PHP Code Execution
63RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nagios3 - 'history.cgi' Host Command Execution (Metasploit)
CVE-2012-6096—remotelinux16 ene 2013
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle Application Framework - Diagnostic Mode Bypass
CVE-2013-0397—webappsjsp16 ene 2013
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
freeSSHd 1.2.6 - Authentication Bypass (Metasploit)
CVE-2012-6066—remotewindows15 ene 2013
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpShop 2.0 - SQL Injection
CVE-2008-0681—webappsphp14 ene 2013
SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpShop 2.0 - SQL Injection
CVE-2009-4571—webappsphp14 ene 2013
Multiple SQL injection vulnerabilities in index.php in PhpShop 0.8.1 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Nagios3 - 'history.cgi' Remote Command Execution
CVE-2012-6096—remotemultiple13 ene 2013
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect
CVE-2013-4266—webappsphp13 ene 2013
20RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect
CVE-2013-5123—webappsphp13 ene 2013
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh
23RIESGO
abrir ↗
GitHub PoC★ 5
Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156
CVE-2013-0156—12 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
GitHub PoC
crack repo from jnunemaker but with version 0.1.8 and rails CVE-2013-0156 vulnerability fixed
CVE-2013-0156—11 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
GitHub PoC★ 1
Inspect all of your heroku apps to see if they are running a vulnerable version of Rails
CVE-2013-0156—11 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet JMX - Remote Code Execution (Metasploit) (1)
CVE-2013-0422CRITICALbajo ataqueransomwareremotejava11 ene 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using
100RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2013-0156—11 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP Bypass) (MS12-037)
CVE-2012-1876—remotewindows10 ene 2013
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir ↗
Metasploit600
Java Applet Reflection Type Confusion Remote Code Execution
CVE-2013-2423LOWbajo ataque10 ene 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and
95RIESGO
abrir ↗
Metasploit600
Java Applet JMX Remote Code Execution
CVE-2013-0422CRITICALbajo ataqueransomware10 ene 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using
100RIESGO
abrir ↗
Exploit-DB
Nero MediaHome 4.5.8.0 - Denial of Service
CVE-2012-5877—doswindows10 ene 2013
Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and cr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ruby on Rails - XML Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0156—remotemultiple10 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Option Element Use-After-Free (MS11-081) (Metasploit)
CVE-2011-1996—remotewindows10 ene 2013
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RIESGO
abrir ↗
Exploit-DB
Nero MediaHome 4.5.8.0 - Denial of Service
CVE-2012-5876—doswindows10 ene 2013
Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c
23RIESGO
abrir ↗
Metasploit600
Java Applet Driver Manager Privileged toString() Remote Code Execution
CVE-2013-1488—10 ene 2013
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remo
60RIESGO
abrir ↗
GitHub PoC
Silly Rails App to demonstrate vuln CVE-2013-0156
CVE-2013-0156—10 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Quick.CMS / Quick.Cart - Cross-Site Scripting
CVE-2012-6430—webappsphp09 ene 2013
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samsung Kies - Remote Buffer Overflow
CVE-2012-6429—remotewindows09 ene 2013
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7
28RIESGO
abrir ↗
← anteriorpágina 1159 / 2713siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.