Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 3D Acceleration Multiple Vulnerabilities
CVE-2014-0983dosmultiple12 mar 2014
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RIESGO
abrir
Exploit-DBVexDay Proof
Procentia IntelliPen 1.1.12.1520 - 'data.aspx' Blind SQL Injection
CVE-2014-2043webappsasp12 mar 2014
SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows re
23RIESGO
abrir
Exploit-DB
Huawei Technologies eSpace Meeting Service 1.0.0.23 - Local Privilege Escalation
CVE-2014-3222localwindows12 mar 2014
In Huawei eSpace Meeting with software V100R001C03SPC201 and the earlier versions, attackers that obtain the permissions
23RIESGO
abrir
Metasploit300
MS14-012 Microsoft Internet Explorer TextRange Use-After-Free
CVE-2014-030711 mar 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause
60RIESGO
abrir
Metasploit200
VirtualBox 3D Acceleration Virtual Machine Escape
CVE-2014-098311 mar 2014
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RIESGO
abrir
Metasploit300
Yokogawa CS3000 BKESimmgr.exe Buffer Overflow
CVE-2014-078210 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector - Backup Client Service Remote Code Execution (Metasploit)
CVE-2013-2347remotewindows10 mar 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DBVexDay Proof
SolidWorks Workgroup PDM 2014 - 'pdmwService.exe' Arbitrary File Write (Metasploit)
CVE-2014-100015remotewindows10 mar 2014
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir
Metasploit300
Yokogawa CENTUM CS 3000 BKBCopyD.exe Buffer Overflow
CVE-2014-078410 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RIESGO
abrir
Metasploit200
Yokogawa CENTUM CS 3000 BKHOdeq.exe Buffer Overflow
CVE-2014-078310 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
75RIESGO
abrir
Metasploit600
ifwatchd Privilege Escalation
CVE-2014-253310 mar 2014
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RIESGO
abrir
Metasploit300
Yokogawa CENTUM CS 3000 BKCLogSvr.exe Heap Buffer Overflow
CVE-2014-078110 mar 2014
Yokogawa CENTUM CS 3000 Heap-based Buffer Overflow
48RIESGO
abrir
Exploit-DBVexDay Proof
QNX 6.4.x/6.5.x ifwatchd - Local Privilege Escalation
CVE-2014-2533localqnx10 mar 2014
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS 4.2.1 - 'facetime-audio://' Security Bypass
CVE-2013-6835remoteios10 mar 2014
TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime au
23RIESGO
abrir
Exploit-DBVexDay Proof
ownCloud 4.0.x/4.5.x - 'upload.php?Filename' Remote Code Execution
CVE-2014-2044webappsmultiple10 mar 2014
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RIESGO
abrir
Exploit-DBVexDay Proof
QNX 6.4.x/6.5.x pppoectl - Information Disclosure
CVE-2014-2534localqnx10 mar 2014
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by rea
23RIESGO
abrir
Exploit-DBVexDay Proof
GetGo Download Manager 4.9.0.1982 - HTTP Response Header Buffer Overflow Remote Code Execution
CVE-2014-2206remotewindows09 mar 2014
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RIESGO
abrir
Metasploit300
GetGo Download Manager HTTP Response Buffer Overflow
CVE-2014-220609 mar 2014
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RIESGO
abrir
Metasploit600
Dell KACE K1000 File Upload
CVE-2014-125113CRITICAL07 mar 2014
Dell/Quest KACE K1000 Unauthenticated File Upload RCE
43RIESGO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-009406 mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-011406 mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-011206 mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0114remotemultiple06 mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0112remotemultiple06 mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0094remotemultiple06 mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
Exploit-DB
OpenDocMan 1.2.7 - Multiple Vulnerabilities
CVE-2014-2317webappsphp05 mar 2014
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Metasploit0
Vtiger Install Unauthenticated Remote Command Execution
CVE-2014-226805 mar 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RIESGO
abrir
Exploit-DBVexDay Proof
ALLPlayer - '.m3u' Local Buffer Overflow (Metasploit)
CVE-2013-7409localwindows05 mar 2014
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Exploit-DB
OpenDocMan 1.2.7 - Multiple Vulnerabilities
CVE-2014-1945webappsphp05 mar 2014
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DB
Ilch CMS 2.0 - Persistent Cross-Site Scripting
CVE-2014-1944webappsphp05 mar 2014
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir
anteriorpágina 1111 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.