Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
HP Data Protector - Backup Client Service Directory Traversal (Metasploit)
CVE-2013-6194remotewindows24 ene 2014
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 ene 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RIESGO
abrir
Exploit-DBVexDay Proof
Skybluecanvas CMS 1.1 r248-03 - Remote Command Execution
CVE-2014-1683webappsphp24 ene 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir
Exploit-DBVexDay Proof
GoToMeeting for Android - Multiple Local Information Disclosure Vulnerabilities
CVE-2014-1664localandroid23 ene 2014
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
MuPDF 1.3 - 'xps_parse_color()' Stack Buffer Overflow
CVE-2014-2013localwindows20 ene 2014
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote a
28RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Sexy polling 1.0.8 - 'answer_id' SQL Injection
CVE-2013-7219webappsphp16 ene 2014
SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a
23RIESGO
abrir
Exploit-DBVexDay Proof
Atmail Webmail Server - Email Body HTML Injection
CVE-2013-6017webappsphp14 ene 2014
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Supply Chain Products Suite - Remote Security
CVE-2013-5880remotemultiple14 ene 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir
Exploit-DBVexDay Proof
SerComm Device - Remote Code Execution (Metasploit)
CVE-2014-0659remotehardware14 ene 2014
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
CVE-2013-2251CRITICALbajo ataquewebappsmultiple14 ene 2014
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir
Exploit-DBVexDay Proof
DomPHP 0.83 - SQL Injection
CVE-2014-10038webappsphp13 ene 2014
SQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections
CVE-2014-1671webappsphp13 ene 2014
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot
23RIESGO
abrir
Exploit-DBVexDay Proof
UAEPD Shopping Script - 'products.php' Multiple SQL Injections
CVE-2014-1618webappsphp08 ene 2014
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
UAEPD Shopping Script - 'news.php?id' SQL Injection
CVE-2014-1618webappsphp08 ene 2014
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_infraction_codes.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/health_allergies.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/Admin_change_Password.php' Cross-Site Request Forgery (Admin Password Manipulation)
CVE-2014-1915webappsphp07 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_terms.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_school_names.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.4.0 SOAP - AddEmailAttachment Arbitrary File Upload (Metasploit)
CVE-2013-3214remotephp07 ene 2014
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_generations.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_grades.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_subjects.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_sgrades.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_school_years.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Forms Viewer - Unicode Buffer Overflow (Metasploit)
CVE-2013-5447localwindows07 ene 2014
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_titles.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_relations.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_media_codes_1.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/add_topic.php' Cross-Site Request Forgery (Topic Creation)
CVE-2014-1915webappsphp07 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.