Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.403exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
81.404 exploits
GitHub PoC★ 1
Inspect all of your heroku apps to see if they are running a vulnerable version of Rails
CVE-2013-0156—11 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2013-0156—11 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Java Applet JMX - Remote Code Execution (Metasploit) (1)
CVE-2013-0422CRITICALbajo ataqueransomwareremotejava11 ene 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using
100RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Option Element Use-After-Free (MS11-081) (Metasploit)
CVE-2011-1996—remotewindows10 ene 2013
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RIESGO
abrir ↗
Exploit-DB
Nero MediaHome 4.5.8.0 - Denial of Service
CVE-2012-5876—doswindows10 ene 2013
Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c
23RIESGO
abrir ↗
GitHub PoC
Silly Rails App to demonstrate vuln CVE-2013-0156
CVE-2013-0156—10 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ruby on Rails - XML Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0156—remotemultiple10 ene 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗
Metasploit600
Java Applet Reflection Type Confusion Remote Code Execution
CVE-2013-2423LOWbajo ataque10 ene 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and
95RIESGO
abrir ↗
Metasploit600
Java Applet JMX Remote Code Execution
CVE-2013-0422CRITICALbajo ataqueransomware10 ene 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using
100RIESGO
abrir ↗
Metasploit600
Java Applet Driver Manager Privileged toString() Remote Code Execution
CVE-2013-1488—10 ene 2013
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remo
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP Bypass) (MS12-037)
CVE-2012-1876—remotewindows10 ene 2013
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir ↗
Exploit-DB
Nero MediaHome 4.5.8.0 - Denial of Service
CVE-2012-5877—doswindows10 ene 2013
Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and cr
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Prizm Content Connect - Arbitrary File Upload
CVE-2012-5190—webappsphp09 ene 2013
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Samsung Kies - Remote Buffer Overflow
CVE-2012-6429—remotewindows09 ene 2013
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7
28RIESGO
abrir ↗
Metasploit600
BigAnt Server DUPF Command Arbitrary File Upload
CVE-2012-6274—09 ene 2013
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to
50RIESGO
abrir ↗
Metasploit300
BigAnt Server 2 SCH And DUPF Buffer Overflow
CVE-2012-6275—09 ene 2013
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Quick.CMS / Quick.Cart - Cross-Site Scripting
CVE-2012-6430—webappsphp09 ene 2013
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dell OpenManage Server Administrator - Cross-Site Scripting
CVE-2012-6272—remotemultiple09 ene 2013
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Cognos - 'tm1admsd.exe' Remote Overflow (Metasploit)
CVE-2012-0202—remotewindows08 ene 2013
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2
50RIESGO
abrir ↗
Exploit-DB
Advantech Webaccess HMI/SCADA Software - Persistence Cross-Site Scripting
CVE-2013-2299—webappsasp08 ene 2013
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allo
23RIESGO
abrir ↗
Metasploit600
Firefox 17.0.1 Flash Privileged Code Injection
CVE-2013-0757—08 ene 2013
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
WordPress Plugin Google Document Embedder - Arbitrary File Disclosure (Metasploit)
CVE-2012-4915—webappsphp08 ene 2013
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t
50RIESGO
abrir ↗
Metasploit300
Firefox XMLSerializer Use After Free
CVE-2013-0753—08 ene 2013
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox b
50RIESGO
abrir ↗
Metasploit600
Firefox 17.0.1 Flash Privileged Code Injection
CVE-2013-0758—08 ene 2013
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)
CVE-2013-0758—localmultiple08 ene 2013
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)
CVE-2013-0757—localmultiple08 ene 2013
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)
CVE-2012-6315—remotemultiple07 ene 2013
35RIESGO
abrir ↗
Metasploit600
Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
CVE-2012-6315—07 ene 2013
35RIESGO
abrir ↗
Metasploit300
Foxit Reader Plugin URL Processing Buffer Overflow
CVE-2013-10068CRITICAL07 ene 2013
Foxit Reader <= 5.4.5.0114 Plugin URL Processing Buffer Overflow
43RIESGO
abrir ↗
Metasploit600
Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
CVE-2013-0209—07 ene 2013
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for reque
50RIESGO
abrir ↗
← anteriorpágina 1160 / 2714siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.