Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
Oracle Java lookUpByteBI - Heap Buffer Overflow
CVE-2013-2470doswindows03 sep 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 U
28RIESGO
abrir
Exploit-DB
Zoom Telephonics ADSL Modem/Router - Multiple Vulnerabilities
CVE-2013-5630webappshardware03 sep 2013
20RIESGO
abrir
Exploit-DB
Zoom Telephonics ADSL Modem/Router - Multiple Vulnerabilities
CVE-2013-5621webappshardware03 sep 2013
20RIESGO
abrir
Exploit-DB
Zoom Telephonics ADSL Modem/Router - Multiple Vulnerabilities
CVE-2013-5625webappshardware03 sep 2013
20RIESGO
abrir
Exploit-DB
Zoom Telephonics ADSL Modem/Router - Multiple Vulnerabilities
CVE-2013-5627webappshardware03 sep 2013
20RIESGO
abrir
Exploit-DB
WordPress Plugin IndiaNIC Testimonial - Multiple Vulnerabilities
CVE-2013-5673webappsphp03 sep 2013
SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.8.4 - Local Privilege Escalation
CVE-2013-1775localosx30 ago 2013
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - XMLSerializer Use-After-Free (Metasploit)
CVE-2013-0753remotewindows29 ago 2013
Use-after-free vulnerability in the serializeToStream implementation in the XMLSerializer component in Mozilla Firefox b
50RIESGO
abrir
Exploit-DBVexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
CVE-2013-4980doshardware29 ago 2013
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Sudo Password Bypass (Metasploit)
CVE-2013-1775localosx29 ago 2013
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RIESGO
abrir
Exploit-DBVexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
CVE-2013-4981doshardware29 ago 2013
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi
23RIESGO
abrir
Exploit-DBVexDay Proof
HP LoadRunner - lrFileIOService ActiveX Remote Code Execution (Metasploit)
CVE-2013-2370remotewindows29 ago 2013
Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown ve
50RIESGO
abrir
Exploit-DBVexDay Proof
AVTECH DVR Firmware 1017-1003-1009-1003 - Multiple Vulnerabilities
CVE-2013-4982doshardware29 ago 2013
AVTECH AVN801 DVR has a security bypass via the administration login captcha
43RIESGO
abrir
Exploit-DBVexDay Proof
VMware - Setuid VMware-mount Unsafe popen(3) (Metasploit)
CVE-2013-1662locallinux29 ago 2013
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RIESGO
abrir
Exploit-DBVexDay Proof
Aloaha PDF Suite - Remote Stack Buffer Overflow
CVE-2013-4978remotewindows28 ago 2013
Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp 5.63 - 'winamp.ini' Local Overflow
CVE-2013-4694localwindows26 ago 2013
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Endeca Server - Remote Command Execution (Metasploit)
CVE-2013-3763remotewindows26 ago 2013
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows rem
50RIESGO
abrir
Exploit-DB
Loftek Nexus 543 IP Cameras - Multiple Vulnerabilities
CVE-2013-3314webappshardware26 ago 2013
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2)
23RIESGO
abrir
Exploit-DB
libtiff 3.9.5 - Integer Overflow
CVE-2013-5575doslinux26 ago 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
cm3 Acora CMS - 'top.aspx' Information Disclosure
CVE-2013-4727webappsphp26 ago 2013
DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
SearchBlox - Multiple Information Disclosure Vulnerabilities
CVE-2013-3597webappsjava23 ago 2013
servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords v
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware - Setuid VMware-mount Popen lsb_release Privilege Escalation
CVE-2013-1662locallinux22 ago 2013
vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allo
38RIESGO
abrir
Exploit-DB
Samba 3.5.22/3.6.17/4.0.8 - nttrans Reply Integer Overflow
CVE-2013-4124doslinux22 ago 2013
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.
50RIESGO
abrir
Exploit-DBVexDay Proof
Foreman (RedHat OpenStack/Satellite) - users/create Mass Assignment (Metasploit)
CVE-2013-2113webappslinux22 ago 2013
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users w
43RIESGO
abrir
Exploit-DB
Netgear ProSafe - Information Disclosure
CVE-2013-4775webappshardware22 ago 2013
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with
28RIESGO
abrir
Exploit-DB
Netgear ProSafe - Denial of Service
CVE-2013-4776doshardware22 ago 2013
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
CVE-2008-4423webappsphp22 ago 2013
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
Ovidentia 7.9.4 - Multiple Vulnerabilities
CVE-2008-3918webappsphp22 ago 2013
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DB
DeWeS 0.4.2 - Directory Traversal
CVE-2013-4900webappswindows22 ago 2013
Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Xibo - Cross-Site Request Forgery
CVE-2013-4889webappsphp21 ago 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attac
23RIESGO
abrir
anteriorpágina 248 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.