Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2013-0074HIGHbajo ataqueransomwareremotewindows27 nov 2013
Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML obj
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Roller - OGNL Injection (Metasploit)
CVE-2013-4212remotejava27 nov 2013
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Unsafe Memory Access (MS12-022) (Metasploit)
CVE-2012-0016remotewindows27 nov 2013
Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CardSpaceClaimCollection ActiveX Integer Underflow (MS13-090) (Metasploit)
CVE-2013-3918HIGHbajo ataqueremotewindows27 nov 2013
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RIESGO
abrir
Exploit-DBVexDay Proof
DesktopCentral AgentLogUpload - Arbitrary File Upload (Metasploit)
CVE-2014-5007remotewindows25 nov 2013
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RIESGO
abrir
Exploit-DBVexDay Proof
Netgear ReadyNAS - Perl Code Evaluation (Metasploit)
CVE-2013-2751remotehardware25 nov 2013
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator
60RIESGO
abrir
Exploit-DBVexDay Proof
DesktopCentral AgentLogUpload - Arbitrary File Upload (Metasploit)
CVE-2013-7390remotewindows25 nov 2013
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Ajaxfs 2 Plugin - SQL Injection
CVE-2013-6936webappsphp24 nov 2013
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Blue Wrench Video Widget - Cross-Site Request Forgery
CVE-2013-6797webappsphp23 nov 2013
Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin be
23RIESGO
abrir
Exploit-DBVexDay Proof
Light Alloy 4.7.3 - '.m3u' Local Buffer Overflow (SEH Unicode)
CVE-2013-6874localwindows22 nov 2013
Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a l
23RIESGO
abrir
Exploit-DBVexDay Proof
Thomson Reuters Velocity Analytics - Remote Code Injection
CVE-2013-5912remotehardware22 nov 2013
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute
35RIESGO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6830remotelinux20 nov 2013
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6829remotelinux20 nov 2013
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacha
60RIESGO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6831remotelinux20 nov 2013
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict
23RIESGO
abrir
Exploit-DBVexDay Proof
DeepOfix SMTP Server 3.3 - Authentication Bypass
CVE-2013-6796remotelinux19 nov 2013
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RIESGO
abrir
Exploit-DBVexDay Proof
Nginx 1.1.17 - URI Processing SecURIty Bypass
CVE-2013-4547remotemultiple19 nov 2013
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RIESGO
abrir
Exploit-DBVexDay Proof
Supermicro Onboard IPMI - 'close_window.cgi' Remote Buffer Overflow (Metasploit)
CVE-2013-3623remotehardware18 nov 2013
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - '.wstyle' Local Buffer Overflow (SEH)
CVE-2013-6937localwindows14 nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Altiris DS - SQL Injection (Metasploit)
CVE-2008-2286remotewindows13 nov 2013
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allow
50RIESGO
abrir
Exploit-DBVexDay Proof
Testa OTMS - Multiple SQL Injections
CVE-2013-6873webappsphp13 nov 2013
SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-3528webappsphp08 nov 2013
Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack
23RIESGO
abrir
Exploit-DBVexDay Proof
Vivotek IP Cameras - RTSP Authentication Bypass
CVE-2013-4985webappshardware08 nov 2013
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla Forums 2.0 < 2.0.18.5 - 'class.utilitycontroller.php' PHP Object Injection
CVE-2013-2749webappsphp08 nov 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2)
CVE-2013-6364webappsphp08 nov 2013
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4468remotelinux08 nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-4467remotelinux08 nov 2013
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RIESGO
abrir
Exploit-DBVexDay Proof
VICIdial Manager - Send OS Command Injection (Metasploit)
CVE-2013-7382remotelinux08 nov 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t
23RIESGO
abrir
Exploit-DBVexDay Proof
Hanso Player 2.5.0 - 'm3u' Buffer Overflow (Denial of Service)
CVE-2013-7280doswindows05 nov 2013
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Signature Verification Security Bypass
CVE-2013-6792remoteandroid04 nov 2013
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
23RIESGO
abrir
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - Local Buffer Overflow (SEH)
CVE-2013-6935localwindows01 nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.