Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection (Metasploit)
CVE-2013-2121remotelinux23 jul 2013
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RIESGO
abrir
Exploit-DBVexDay Proof
HP Managed Printing Administration - jobAcct Remote Command Execution (Metasploit)
CVE-2011-4166remotewindows22 jul 2013
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
CVE-2013-1017remotewindows22 jul 2013
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.0.7 - Remote (Metasploit)
CVE-2013-4730remotewindows22 jul 2013
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Exploit-DBVexDay Proof
Anchor CMS 0.9.1 - Persistent Cross-Site Scripting
CVE-2013-5099webappsphp18 jul 2013
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Squid 3.3.5 - Denial of Service (PoC)
CVE-2013-4123doslinux16 jul 2013
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of
45RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.2.3 - Multiple Open Redirections
CVE-2013-2248remotemultiple16 jul 2013
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to
60RIESGO
abrir
Exploit-DBVexDay Proof
BlazeDVD Pro Player 6.1 - Direct RET Local Stack Buffer Overflow
CVE-2006-6199localwindows16 jul 2013
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir
Exploit-DBVexDay Proof
ReadyMedia - Remote Heap Buffer Overflow
CVE-2013-2739remotewindows15 jul 2013
MiniDLNA has heap-based buffer overflow
23RIESGO
abrir
Exploit-DBVexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
CVE-2013-3248localwindows13 jul 2013
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wi
43RIESGO
abrir
Exploit-DBVexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
CVE-2013-0742localwindows13 jul 2013
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenEMR 4.1 - 'note' HTML Injection
CVE-2013-4620webappsphp12 jul 2013
Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Pie Register - 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4954webappsphp12 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before
23RIESGO
abrir
Exploit-DBVexDay Proof
S9Y Serendipity 1.6.2 - 'serendipity_admin_image_selector.php' Cross-Site Scripting
CVE-2013-5314webappsphp12 jul 2013
Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - Remote Stack Buffer Overflow
CVE-2013-5019remotewindows11 jul 2013
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin miniBB - SQL Injection / Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-5020webappsphp11 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
Mintboard - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-4951webappsphp10 jul 2013
Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Exploit-DBVexDay Proof
ERS Viewer 2013 - '.ERS' File Handling Buffer Overflow (Metasploit)
CVE-2013-3482localwindows09 jul 2013
Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache CXF < 2.5.10/2.6.7/2.7.4 - Denial of Service
CVE-2013-2160dosmultiple09 jul 2013
The streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote att
35RIESGO
abrir
Exploit-DBVexDay Proof
Zoom Telephonics (Multiple Devices) - Multiple Vulnerabilities
CVE-2013-5620remotehardware09 jul 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'APK' code Remote Security Bypass
CVE-2013-4787remoteandroid03 jul 2013
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EPATHOBJ::pprFlattenRec' Local Privilege Escalation (Metasploit)
CVE-2013-3661localwindows02 jul 2013
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RIESGO
abrir
Exploit-DBVexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4950webappsphp02 jul 2013
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Exploit-DBVexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4948webappsphp02 jul 2013
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
Intelligent Platform Management Interface - Information Disclosure
CVE-2013-4786remotemultiple02 jul 2013
The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote
60RIESGO
abrir
Exploit-DBVexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4949webappsphp02 jul 2013
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code b
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp 5.63 - Stack Buffer Overflow
CVE-2013-4694doswindows02 jul 2013
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EPATHOBJ::pprFlattenRec' Local Privilege Escalation (Metasploit)
CVE-2013-3130localwindows02 jul 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
RealNetworks RealPlayer - Denial of Service
CVE-2013-3299dosmultiple02 jul 2013
RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Category Grid View Gallery - 'ID' Cross-Site Scripting
CVE-2013-4117webappsphp02 jul 2013
Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for
43RIESGO
abrir
anteriorpágina 103 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.