Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DBVexDay Proof
GOM Video Converter 1.1.0.60 - '.wav' Memory Corruption (PoC)
CVE-2014-2671doswindows24 mar 2014
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 11.0.5721.5230 - Memory Corruption (PoC)
CVE-2014-2671doswindows24 mar 2014
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir
Exploit-DBVexDay Proof
GOM Media Player (GOMMP) 2.2.56.5183 - Memory Corruption (PoC)
CVE-2014-2671doswindows24 mar 2014
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir
Metasploit300
Katello (Red Hat Satellite) users/update_roles Missing Authorization
CVE-2013-214324 mar 2014
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - TextRange Use-After-Free (MS14-012) (Metasploit)
CVE-2014-0307remotewindows22 mar 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause
60RIESGO
abrir
Exploit-DBVexDay Proof
Horde Framework - Unserialize PHP Code Execution (Metasploit)
CVE-2014-1691remotephp22 mar 2014
The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to c
50RIESGO
abrir
Metasploit600
FreePBX config.php Remote Code Execution
CVE-2014-190321 mar 2014
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RIESGO
abrir
Metasploit600
SePortal SQLi Remote Code Execution
CVE-2008-519120 mar 2014
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir
Metasploit400
Wireshark wiretap/mpeg.c Stack Buffer Overflow
CVE-2014-229920 mar 2014
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RIESGO
abrir
Exploit-DB
OXID eShop < 4.7.11/5.0.11 / < 4.8.4/5.1.4 - Multiple Vulnerabilities
CVE-2014-2016webappsphp20 mar 2014
Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier,
23RIESGO
abrir
Exploit-DB
OXID eShop < 4.7.11/5.0.11 / < 4.8.4/5.1.4 - Multiple Vulnerabilities
CVE-2014-2017webappsphp20 mar 2014
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition
23RIESGO
abrir
Exploit-DBVexDay Proof
MP3Info 0.8.5a - Local Buffer Overflow (SEH)
CVE-2006-2465localwindows19 mar 2014
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RIESGO
abrir
Exploit-DBVexDay Proof
GNUBoard 4.3x - 'ajax.autosave.php' Multiple SQL Injections
CVE-2014-2339webappsphp19 mar 2014
Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authen
23RIESGO
abrir
Exploit-DB
McAfee Asset Manager 6.6 - Multiple Vulnerabilities
CVE-2014-2588webappsjsp19 mar 2014
Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated user
23RIESGO
abrir
Exploit-DB
McAfee Asset Manager 6.6 - Multiple Vulnerabilities
CVE-2014-2586webappsjsp19 mar 2014
Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote atta
23RIESGO
abrir
Exploit-DB
McAfee Asset Manager 6.6 - Multiple Vulnerabilities
CVE-2014-2587webappsjsp19 mar 2014
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated user
23RIESGO
abrir
Exploit-DBVexDay Proof
SePortal 2.5 - SQL Injection (2)
CVE-2008-5191remotephp19 mar 2014
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir
Exploit-DBVexDay Proof
Free Download Manager - Stack Buffer Overflow
CVE-2014-2087doswindows17 mar 2014
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download
28RIESGO
abrir
Metasploit600
Firefox WebIDL Privileged Javascript Injection
CVE-2014-151017 mar 2014
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and Se
60RIESGO
abrir
Metasploit600
Firefox WebIDL Privileged Javascript Injection
CVE-2014-151117 mar 2014
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remo
60RIESGO
abrir
Exploit-DB
iOS 7 - Kernel Mode Memory Corruption
CVE-2014-1287dosios17 mar 2014
USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code
23RIESGO
abrir
Exploit-DB
Nginx 1.4.0 (Generic Linux x64) - Remote Overflow
CVE-2013-2028remotelinux_x86-6415 mar 2014
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
Exploit-DBVexDay Proof
OpenX 2.8.x - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2013-5954webappsphp15 mar 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack
23RIESGO
abrir
Exploit-DBVexDay Proof
MicroP 0.1.1.1600 - '.mppl' Local Stack Buffer Overflow
CVE-2010-5299localwindows14 mar 2014
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir
Exploit-DBVexDay Proof
Procentia IntelliPen 1.1.12.1520 - 'data.aspx' Blind SQL Injection
CVE-2014-2043webappsasp12 mar 2014
SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows re
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities
CVE-2014-0981dosmultiple12 mar 2014
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x bef
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities
CVE-2014-0982dosmultiple12 mar 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities
CVE-2014-0983dosmultiple12 mar 2014
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RIESGO
abrir
Exploit-DBVexDay Proof
Yokogawa CENTUM CS 3000 - 'BKBCopyD.exe' Remote Buffer Overflow (Metasploit)
CVE-2014-0784remotewindows12 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RIESGO
abrir
Exploit-DBVexDay Proof
FreePBX 2.11.0 - Remote Command Execution
CVE-2014-1903webappsphp12 mar 2014
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RIESGO
abrir
anteriorpágina 1110 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.