Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DBVexDay Proof
Oracle Forms and Reports - Remote Code Execution (Metasploit)
CVE-2012-3152CRITICALbajo ataqueremotewindows18 feb 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (1)
CVE-2013-5019remotewindows18 feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir
Exploit-DBVexDay Proof
i-doit Pro - 'objID' SQL Injection
CVE-2014-1597webappsphp17 feb 2014
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot
23RIESGO
abrir
Exploit-DB
HP Data Protector - 'EXEC_BAR' Remote Command Execution
CVE-2013-2347remotewindows16 feb 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DB
ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH)
CVE-2014-2030localwindows16 feb 2014
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remot
28RIESGO
abrir
Exploit-DB
ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH)
CVE-2014-1947localwindows16 feb 2014
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Eudora Qualcomm WorldMail 9.0.333.0 - IMAPd Service UID Buffer Overflow
CVE-2014-10031remotewindows16 feb 2014
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DB
CA 2E Web Option 8.1.2 - Authentication Bypass
CVE-2014-1219webappsmultiple13 feb 2014
CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which
23RIESGO
abrir
Metasploit300
MS14-012 Microsoft Internet Explorer CMarkup Use-After-Free
CVE-2014-0322HIGHbajo ataque13 feb 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Metasploit600
Linksys E-Series TheMoon Remote Command Injection
CVE-2025-34037CRITICAL13 feb 2014
Linksys Routers E/WAG/WAP/WES/WET/WRT-Series
85RIESGO
abrir
Exploit-DBVexDay Proof
Easy CD-DA Recorder - '.pls' Local Buffer Overflow (Metasploit)
CVE-2010-2343localwindows13 feb 2014
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Commons FileUpload and Apache Tomcat - Denial of Service
CVE-2014-0050dosmultiple12 feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1842webappswindows11 feb 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1843webappswindows11 feb 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Exploit-DB
WordPress Plugin BuddyPress 1.9.1 - Privilege Escalation
CVE-2014-1889webappsphp11 feb 2014
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain
28RIESGO
abrir
Exploit-DBVexDay Proof
Tableau Server < 8.0.7 / < 8.1.2 - Blind SQL Injection
CVE-2014-1204webappswindows11 feb 2014
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RIESGO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1841webappswindows11 feb 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Exploit-DB
Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation
CVE-2013-6282HIGHbajo ataquelocalarm11 feb 2014
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenuEx Win32k NULL Page (MS13-081) (Metasploit)
CVE-2013-3881localwindows11 feb 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RIESGO
abrir
Metasploit500
MS14-009 .NET Deployment Service IE Sandbox Escape
CVE-2014-025711 feb 2014
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RIESGO
abrir
Metasploit600
Fritz!Box Webcm Unauthenticated Command Injection
CVE-2014-972711 feb 2014
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t
60RIESGO
abrir
Exploit-DBVexDay Proof
KingScada - kxClientDownload.ocx ActiveX Remote Code Execution (Metasploit)
CVE-2013-2827remotewindows11 feb 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir
Exploit-DB
ZTE ZXV10 W300 Router - Hard-Coded Credentials
CVE-2014-0329webappshardware09 feb 2014
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - '.pui' Local Buffer Overflow (SEH)
CVE-2014-0980localwindows08 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
CVE-2014-10033webappsphp07 feb 2014
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RIESGO
abrir
Exploit-DB
CTERA 3.2.29.0/3.2.42.0 - Persistent Cross-Site Scripting
CVE-2013-2639webappsphp07 feb 2014
Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote
23RIESGO
abrir
Exploit-DB
AuraCMS 2.3 - Multiple Vulnerabilities
CVE-2014-1401webappsphp07 feb 2014
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary
23RIESGO
abrir
Exploit-DB
doorGets CMS 5.2 - SQL Injection
CVE-2014-1459webappsphp07 feb 2014
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RIESGO
abrir
Exploit-DBVexDay Proof
Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit)
CVE-2013-4710remotehardware07 feb 2014
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - Buffer Overflow
CVE-2014-0980doswindows06 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
anteriorpágina 1114 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.