Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
Juniper Junos J-Web - Privilege Escalation
CVE-2013-6618webappsphp12 nov 2013
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,
28RIESGO
abrir
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' File Local Buffer Overflow (SEH Unicode)
CVE-2013-7409localwindows12 nov 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4467remotelinux08 nov 2013
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RIESGO
abrir
Exploit-DBVexDay Proof
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2)
CVE-2013-6364webappsphp08 nov 2013
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RIESGO
abrir
Exploit-DBVexDay Proof
Vivotek IP Cameras - RTSP Authentication Bypass
CVE-2013-4985webappshardware08 nov 2013
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5220webappshardware08 nov 2013
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device
23RIESGO
abrir
Exploit-DB
appRain 3.0.2 - Blind SQL Injection
CVE-2013-6058webappsphp08 nov 2013
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-3528webappsphp08 nov 2013
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5219webappshardware08 nov 2013
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrar
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5037webappshardware08 nov 2013
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-7382remotelinux08 nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t
23RIESGO
abrir
Exploit-DB
Project'Or RIA 3.4.0 - 'objectDetail.php?objectId' SQL Injection
CVE-2013-6164webappsphp08 nov 2013
SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5039webappshardware08 nov 2013
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.1
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5038webappshardware08 nov 2013
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP a
23RIESGO
abrir
Exploit-DB
Sagemcom F@st 3184 2.1.11 - Multiple Vulnerabilities
CVE-2013-5218webappshardware08 nov 2013
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-2749webappsphp08 nov 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4468remotelinux08 nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RIESGO
abrir
Exploit-DBVexDay Proof
Hanso Player 2.5.0 - 'm3u' Buffer Overflow (Denial of Service)
CVE-2013-7280doswindows05 nov 2013
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RIESGO
abrir
Exploit-DB
Apache Tomcat 5.5.25 - Cross-Site Request Forgery
CVE-2013-6357webappsmultiple04 nov 2013
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows re
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Signature Verification Security Bypass
CVE-2013-6792remoteandroid04 nov 2013
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
23RIESGO
abrir
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - Local Buffer Overflow (SEH)
CVE-2013-6935localwindows01 nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir
Exploit-DBVexDay Proof
Zabbix - (Authenticated) Remote Command Execution (Metasploit)
CVE-2013-3628remotelinux31 oct 2013
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir
Exploit-DBVexDay Proof
Moodle - Remote Command Execution (Metasploit)
CVE-2013-3630remotelinux31 oct 2013
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RIESGO
abrir
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2311remotephp31 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.3.0 5.4.0 - (Authenticated) Remote Code Execution (Metasploit)
CVE-2013-3591remotephp31 oct 2013
vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability
50RIESGO
abrir
Exploit-DB
Apache + PHP < 5.3.12 / < 5.4.2 - Remote Code Execution + Scanner
CVE-2012-2336remotephp31 oct 2013
sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not
35RIESGO
abrir
Exploit-DB
Opsview pre 4.4.1 - Blind SQL Injection
CVE-2013-5694webappsphp31 oct 2013
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
NAS4Free - Remote Code Execution (Metasploit)
CVE-2013-3631remotephp31 oct 2013
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RIESGO
abrir
Exploit-DBVexDay Proof
OpenMediaVault Cron - Remote Command Execution (Metasploit)
CVE-2013-3632HIGHremotelinux31 oct 2013
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir
Exploit-DBVexDay Proof
ISPConfig - (Authenticated) Arbitrary PHP Code Execution (Metasploit)
CVE-2013-3629remotephp31 oct 2013
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
50RIESGO
abrir
anteriorpágina 243 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.