Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
iScripts AutoHoster - 'additionalsettings.php' SQL Injection
CVE-2013-7189webappsphp15 dic 2013
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
iScripts AutoHoster - 'invno' SQL Injection
CVE-2013-7189webappsphp15 dic 2013
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
iScripts AutoHoster - 'main_smtp.php' Traversal
CVE-2013-7190webappsphp15 dic 2013
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
iScripts AutoHoster - 'checktransferstatusbck.php' SQL Injection
CVE-2013-7189webappsphp15 dic 2013
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI - 'tfPassword' SQL Injection
CVE-2013-6875remotephp13 dic 2013
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Dynamic Biz Website Builder 'QuickWeb' 1.0 - '/login.asp' Multiple Field SQL Injections / Authentication Bypass
CVE-2013-7192webappsasp13 dic 2013
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Dynamic Biz Website Builder (QuickWeb) 1.0 - '/apps/news-events/newdetail.asp?id' SQL Injection
CVE-2013-7192webappsasp13 dic 2013
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Projoom NovaSFH 3.0.2 - 'upload.php' Arbitrary File Upload
CVE-2014-1214webappsphp13 dic 2013
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Unified Communications Manager - TFTP Service
CVE-2013-7030HIGHlocalhardware12 dic 2013
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RIESGO
abrir
Exploit-DBVexDay Proof
RedHat Piranha - Remote Security Bypass
CVE-2013-6492remotelinux11 dic 2013
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit)
CVE-2013-0632CRITICALbajo ataqueremotemultiple11 dic 2013
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RIESGO
abrir
Exploit-DBVexDay Proof
HP LoadRunner EmulationAdmin - Web Service Directory Traversal (Metasploit)
CVE-2013-4837remotewindows11 dic 2013
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RIESGO
abrir
Exploit-DBVexDay Proof
IcoFX 2.5.0.0 - '.ico' Buffer Overflow (PoC)
CVE-2013-4988doswindows11 dic 2013
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 5 - 'index.php/ajax/api/reputation/vote?nodeid' SQL Injection (Metasploit)
CVE-2013-3522remotephp11 dic 2013
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RIESGO
abrir
Exploit-DBVexDay Proof
eduTrac - 'showmask' Directory Traversal
CVE-2013-7097webappsphp11 dic 2013
Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
eFront 3.6.14 (build 18012) - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2013-7194webappsphp11 dic 2013
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.0.5 - 'ath9k_htc_set_bssid_mask()' Information Disclosure
CVE-2013-4579remotelinux10 dic 2013
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12
28RIESGO
abrir
Exploit-DBVexDay Proof
GOM Player 2.2.53.5169 - '.reg' Local Buffer Overflow (SEH)
CVE-2013-6356localwindows09 dic 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Download Manager Free & Pro 2.5.8 - Persistent Cross-Site Scripting
CVE-2013-7319webappsphp08 dic 2013
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
Zimbra 2009-2013 - Local File Inclusion
CVE-2013-7091webappslinux06 dic 2013
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir
Exploit-DBVexDay Proof
Enorth Webpublisher CMS - 'thisday' SQL Injection
CVE-2013-6985webappsphp06 dic 2013
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows
23RIESGO
abrir
Exploit-DBVexDay Proof
MySQL 5.0.x - IF Query Handling Remote Denial of Service
CVE-2007-2583doslinux04 dic 2013
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RIESGO
abrir
Exploit-DBVexDay Proof
Steinberg MyMp3PRO 5.0 - Local Buffer Overflow (SEH) (DEP Bypass + ROP)
CVE-2013-7186localwindows04 dic 2013
Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'NDPROXY' SYSTEM Privilege Escalation (MS14-002)
CVE-2013-5065HIGHbajo ataquelocalwindows03 dic 2013
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft - Tagged Image File Format '.TIFF' Integer Overflow (Metasploit)
CVE-2013-3906HIGHbajo ataqueremotewindows03 dic 2013
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RIESGO
abrir
Exploit-DBVexDay Proof
Chamilo Lms 1.9.6 - 'profile.php?password' SQL Injection
CVE-2013-6787webappsphp03 dic 2013
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlie
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Prime Data Center Network Manager - Arbitrary File Upload (Metasploit)
CVE-2013-5486remotejava03 dic 2013
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Formcraft - SQL Injection
CVE-2013-7187webappsphp02 dic 2013
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Kingsoft Office Writer 2012 8.1.0.3385 - '.wps' Local Buffer Overflow (SEH)
CVE-2013-3934localwindows30 nov 2013
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader - ASLR + DEP Bypass with Sandbox Bypass
CVE-2013-0640HIGHbajo ataquelocalwindows28 nov 2013
Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute
93RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.