Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (1)
CVE-2013-5019remotewindows18 feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir
Exploit-DBVexDay Proof
i-doit Pro - 'objID' SQL Injection
CVE-2014-1597webappsphp17 feb 2014
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
Eudora Qualcomm WorldMail 9.0.333.0 - IMAPd Service UID Buffer Overflow
CVE-2014-10031remotewindows16 feb 2014
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy CD-DA Recorder - '.pls' Local Buffer Overflow (Metasploit)
CVE-2010-2343localwindows13 feb 2014
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Commons FileUpload and Apache Tomcat - Denial of Service
CVE-2014-0050dosmultiple12 feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir
Exploit-DBVexDay Proof
KingScada - kxClientDownload.ocx ActiveX Remote Code Execution (Metasploit)
CVE-2013-2827remotewindows11 feb 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir
Exploit-DBVexDay Proof
Tableau Server < 8.0.7 / < 8.1.2 - Blind SQL Injection
CVE-2014-1204webappswindows11 feb 2014
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenuEx Win32k NULL Page (MS13-081) (Metasploit)
CVE-2013-3881localwindows11 feb 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - '.pui' Local Buffer Overflow (SEH)
CVE-2014-0980localwindows08 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
CVE-2014-10033webappsphp07 feb 2014
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RIESGO
abrir
Exploit-DBVexDay Proof
Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit)
CVE-2013-4710remotehardware07 feb 2014
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - Buffer Overflow
CVE-2014-0980doswindows06 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DBVexDay Proof
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
CVE-2008-1461remotewindows05 feb 2014
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename arg
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
CVE-2009-3548remotemultiple05 feb 2014
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir
Exploit-DBVexDay Proof
ImpressCMS 1.3.5 - Multiple Vulnerabilities
CVE-2014-1836webappsphp05 feb 2014
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Skybluecanvas CMS - Remote Code Execution (Metasploit)
CVE-2014-1683remotelinux05 feb 2014
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts - Developer Mode OGNL Execution (Metasploit)
CVE-2012-0394remotejava05 feb 2014
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/diagnostic.cgi?ping_ipaddr' Remote Code Execution
CVE-2013-7179remotecgi03 feb 2014
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/reboot.cgi' Remote Reboot (Denial of Service)
CVE-2013-7183doscgi03 feb 2014
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) v
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.10) - 'CONFIG_X86_X32' Arbitrary Write (2)
CVE-2014-0038locallinux02 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.04/13.10 x64) - 'CONFIG_X86_X32=y' Local Privilege Escalation (3)
CVE-2014-0038locallinux_x86-6402 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
MediaWiki 1.22.1 PdfHandler - Remote Code Execution
CVE-2014-1610webappsmultiple01 feb 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'ABOR' Remote Buffer Overflow
CVE-2013-4730remotewindows29 ene 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.07 - 'CWD' Remote Buffer Overflow
CVE-2013-4730remotewindows29 ene 2014
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1632webappsphp28 ene 2014
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the
28RIESGO
abrir
Exploit-DBVexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
CVE-2014-1631webappsphp28 ene 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RIESGO
abrir
Exploit-DBVexDay Proof
Eventum - Insecure File Permissions
CVE-2014-1631webappsphp27 ene 2014
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RIESGO
abrir
Exploit-DBVexDay Proof
MP3Info 0.8.5a - Buffer Overflow
CVE-2006-2465doslinux27 ene 2014
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RIESGO
abrir
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7248webappshardware24 ene 2014
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RIESGO
abrir
Exploit-DBVexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
CVE-2013-7247webappshardware24 ene 2014
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.