Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Machform Form Maker 2 - Multiple Vulnerabilities
CVE-2013-4948webappsphp02 jul 2013
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft PowerPoint 2007 - Crash (PoC)
CVE-2014-2671doswindows01 jul 2013
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir
Exploit-DBVexDay Proof
libvirt - 'virConnectListAllInterfaces' Method Denial of Service
CVE-2013-2218doslinux01 jul 2013
Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.
23RIESGO
abrir
Exploit-DBVexDay Proof
Java Applet - ProviderSkeleton Insecure Invoke Method (Metasploit)
CVE-2013-2460remotemultiple01 jul 2013
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Xorbin Digital Flash Clock - 'widgetUrl' Cross-Site Scripting
CVE-2013-4692webappsphp30 jun 2013
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Xorbin Analog Flash Clock - 'widgetUrl' Cross-Site Scripting
CVE-2013-4692webappsphp30 jun 2013
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
23RIESGO
abrir
Exploit-DBVexDay Proof
YardRadius - Multiple Local Format String Vulnerabilities
CVE-2013-4147localwindows30 jun 2013
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Novell Client 2 SP3 - 'nicm.sys' Local Privilege Escalation (Metasploit)
CVE-2013-3956localwindows_x8626 jun 2013
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RIESGO
abrir
Exploit-DBVexDay Proof
Xaraya - Multiple Cross-Site Scripting Vulnerabilities
CVE-2013-3639webappsphp26 jun 2013
Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 4.0 - 'tracepath' Local Denial of Service
CVE-2013-3792dosmultiple26 jun 2013
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.18, 4.0
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD 9 - Address Space Manipulation Privilege Escalation (Metasploit)
CVE-2013-2171localfreebsd26 jun 2013
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RIESGO
abrir
Exploit-DBVexDay Proof
phpEventCalendar 0.2.3 - Multiple Vulnerabilities
CVE-2007-3519webappsphp24 jun 2013
SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
Top Games Script 1.2 - 'play.php?gid' SQL Injection
CVE-2013-4953webappsphp24 jun 2013
SQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
HP System Management Homepage - JustGetSNMPQueue Command Injection (Metasploit)
CVE-2013-3576remotewindows24 jun 2013
ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands vi
50RIESGO
abrir
Exploit-DBVexDay Proof
MoinMoin - twikidraw Action Traversal Arbitrary File Upload (Metasploit)
CVE-2012-6081remotelinux24 jun 2013
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action
50RIESGO
abrir
Exploit-DBVexDay Proof
MoinMoin - twikidraw Action Traversal Arbitrary File Upload (Metasploit)
CVE-2012-6495remotelinux24 jun 2013
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anyw
28RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD 9.0 < 9.1 - 'mmap/ptrace' Local Privilege Escalation
CVE-2013-2171localfreebsd21 jun 2013
The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEAS
38RIESGO
abrir
Exploit-DBVexDay Proof
Winamp 5.12 - '.m3u' Local Stack Buffer Overflow
CVE-2006-0720localwindows17 jun 2013
Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service
28RIESGO
abrir
Exploit-DBVexDay Proof
Easy LAN Folder Share 3.2.0.100 - Buffer Overflow
CVE-2013-6079doswindows14 jun 2013
Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (applic
23RIESGO
abrir
Exploit-DBVexDay Proof
Monkey HTTP Daemon Mandril Security Plugin - Security Bypass
CVE-2013-2182remotemultiple14 jun 2013
The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restri
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Integer Overflow (MS13-009) (Metasploit)
CVE-2013-2551HIGHbajo ataqueransomwareremotewindows13 jun 2013
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - COALineDashStyleArray Integer Overflow (MS13-009) (Metasploit)
CVE-2013-1298remotewindows13 jun 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin NextGEN Gallery - 'upload.php' Arbitrary File Upload
CVE-2013-3684webappsphp12 jun 2013
NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload
28RIESGO
abrir
Exploit-DBVexDay Proof
Ubiquiti airCam RTSP Service 1.1.5 - Buffer Overflow (PoC)
CVE-2013-1606doshardware12 jun 2013
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RIESGO
abrir
Exploit-DBVexDay Proof
Sony CH / DH Series IP Cameras - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2013-3539remotehardware12 jun 2013
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH2
23RIESGO
abrir
Exploit-DBVexDay Proof
Grandstream Multiple IP Cameras - Cross-Site Request Forgery
CVE-2013-3963remotehardware12 jun 2013
Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD
23RIESGO
abrir
Exploit-DBVexDay Proof
Brickcom Multiple IP Cameras - Cross-Site Request Forgery
CVE-2013-3690remotehardware12 jun 2013
Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100A
28RIESGO
abrir
Exploit-DBVexDay Proof
Java Applet - Driver Manager Privileged 'toString()' Remote Code Execution (Metasploit)
CVE-2013-1488remotemultiple11 jun 2013
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remo
60RIESGO
abrir
Exploit-DBVexDay Proof
Weathermap 0.97c - 'mapname' Local File Inclusion
CVE-2013-3739webappsphp11 jun 2013
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 3.8.9 (x86-64) - 'perf_swevent_init' Local Privilege Escalation (2)
CVE-2013-2094HIGHbajo ataquelocallinux_x86-6411 jun 2013
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
anteriorpágina 104 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.