Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
ManageEngine Support Center Plus Directory Traversal
CVE-2014-10000228 ene 2014
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RIESGO
abrir
Metasploit600
MediaWiki Thumb.php Remote Command Execution
CVE-2014-161028 ene 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir
Metasploit600
SkyBlueCanvas CMS Remote Code Execution
CVE-2014-168328 ene 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir
Metasploit600
Simple E-Document Arbitrary File Upload
CVE-2014-125126CRITICAL23 ene 2014
Simple E-Document Arbitrary File Upload RCE
63RIESGO
abrir
Metasploit600
GE Proficy CIMPLICITY gefebt.exe Remote Code Execution
CVE-2014-075023 ene 2014
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir
Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
CVE-2015-080220 ene 2014
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir
Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
CVE-2014-863620 ene 2014
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir
Metasploit300
Mac OS X Safari file:// Redirection Sandbox Escape
CVE-2015-115516 ene 2014
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allo
23RIESGO
abrir
Metasploit500
Oracle Forms and Reports Remote Code Execution
CVE-2012-315315 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir
Metasploit500
Oracle Forms and Reports Remote Code Execution
CVE-2012-3152CRITICALbajo ataque15 ene 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir
Metasploit400
KingScada kxClientDownload.ocx ActiveX Remote Code Execution
CVE-2013-282714 ene 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir
Metasploit500
HP AutoPass License Server File Upload
CVE-2013-622110 ene 2014
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoP
60RIESGO
abrir
Metasploit600
GetSimpleCMS PHP File Upload Vulnerability
CVE-2013-10032HIGH04 ene 2014
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
36RIESGO
abrir
Metasploit600
HP Data Protector Backup Client Service Remote Code Execution
CVE-2013-234702 ene 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir
Metasploit500
HP Data Protector Backup Client Service Directory Traversal
CVE-2013-619402 ene 2014
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir
Metasploit500
HP Client Automation Command Injection
CVE-2015-149702 ene 2014
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Metasploit500
SerComm Device Remote Code Execution
CVE-2014-065931 dic 2013
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir
Metasploit300
SerComm Network Device Backdoor Detection
CVE-2014-065931 dic 2013
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir
Metasploit300
IBM Lotus Sametime Version Enumeration
CVE-2013-398227 dic 2013
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspeci
23RIESGO
abrir
Metasploit300
IBM Lotus Notes Sametime Room Name Bruteforce
CVE-2013-397727 dic 2013
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine whic
18RIESGO
abrir
Metasploit300
IBM Lotus Notes Sametime User Enumeration
CVE-2013-397527 dic 2013
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remot
23RIESGO
abrir
Metasploit300
RealNetworks RealPlayer Version Attribute Buffer Overflow
CVE-2013-726020 dic 2013
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RIESGO
abrir
Metasploit300
Adobe Flash Player Type Confusion Remote Code Execution
CVE-2013-533110 dic 2013
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RIESGO
abrir
Metasploit300
IcoFX Stack Buffer Overflow
CVE-2013-498810 dic 2013
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir
Metasploit500
MS13-097 Registry Symlink IE Sandbox Escape
CVE-2013-504510 dic 2013
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RIESGO
abrir
Metasploit600
ElasticSearch Dynamic Script Arbitrary Java Execution
CVE-2014-3120HIGHbajo ataque09 dic 2013
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
Metasploit600
Zimbra Collaboration Server LFI
CVE-2013-709106 dic 2013
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir
Metasploit300
IBM Forms Viewer Unicode Buffer Overflow
CVE-2013-544705 dic 2013
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RIESGO
abrir
Metasploit300
Ruby on Rails Action View MIME Memory Exhaustion
CVE-2013-641404 dic 2013
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allo
23RIESGO
abrir
Metasploit200
Windows NTUserMessageCall Win32k Kernel Pool Overflow (Schlamperei)
CVE-2013-130001 dic 2013
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.