Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DBVexDay Proof
Light Alloy 4.7.3 - '.m3u' Local Buffer Overflow (SEH Unicode)
CVE-2013-6874localwindows22 nov 2013
Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a l
23RIESGO
abrir
Metasploit300
Ruby on Rails JSON Processor Floating Point Heap Overflow DoS
CVE-2013-416422 nov 2013
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and tru
30RIESGO
abrir
Exploit-DBVexDay Proof
Thomson Reuters Velocity Analytics - Remote Code Injection
CVE-2013-5912remotehardware22 nov 2013
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute
35RIESGO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6831remotelinux20 nov 2013
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict
23RIESGO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6829remotelinux20 nov 2013
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacha
60RIESGO
abrir
Exploit-DBVexDay Proof
PineApp MailSecure - Remote Command Execution
CVE-2013-6830remotelinux20 nov 2013
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
DeepOfix SMTP Server 3.3 - Authentication Bypass
CVE-2013-6796remotelinux19 nov 2013
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RIESGO
abrir
Metasploit600
Idera Up.Time Monitoring Station 7.0 post2file.php Arbitrary File Upload
CVE-2025-34121CRITICAL19 nov 2013
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RIESGO
abrir
Exploit-DB
Ruckus Wireless Zoneflex 2942 Wireless Access Point - Authentication Bypass
CVE-2013-5030webappshardware19 nov 2013
Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and sub
23RIESGO
abrir
Exploit-DBVexDay Proof
Nginx 1.1.17 - URI Processing SecURIty Bypass
CVE-2013-4547remotemultiple19 nov 2013
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RIESGO
abrir
Exploit-DB
LiveZilla 5.0.1.4 - Remote Code Execution
CVE-2013-6225webappsphp18 nov 2013
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
28RIESGO
abrir
Exploit-DB
Avira Secure Backup 1.0.0.1 Build 3616 - '.reg' Buffer Overflow
CVE-2013-6356doswindows18 nov 2013
20RIESGO
abrir
Exploit-DBVexDay Proof
Supermicro Onboard IPMI - 'close_window.cgi' Remote Buffer Overflow (Metasploit)
CVE-2013-3623remotehardware18 nov 2013
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3613webappshardware18 nov 2013
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access
23RIESGO
abrir
GitHub PoC27
CVE-2013-6282 exploit
CVE-2013-6282HIGHbajo ataque18 nov 2013
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DB
ManageEngine Desktop Central 8.0.0 build < 80293 - Arbitrary File Upload
CVE-2013-7390webappsjsp18 nov 2013
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3615webappshardware18 nov 2013
Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent
23RIESGO
abrir
Exploit-DB
ManageEngine Desktop Central 8.0.0 build < 80293 - Arbitrary File Upload
CVE-2014-5007webappsjsp18 nov 2013
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RIESGO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-6117webappshardware18 nov 2013
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3614webappshardware18 nov 2013
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to o
23RIESGO
abrir
Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
CVE-2013-3612webappshardware18 nov 2013
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which
28RIESGO
abrir
Exploit-DBVexDay Proof
Watermark Master 2.2.23 - '.wstyle' Local Buffer Overflow (SEH)
CVE-2013-6937localwindows14 nov 2013
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Testa OTMS - Multiple SQL Injections
CVE-2013-6873webappsphp13 nov 2013
SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DB
TOSHIBA e-Studio 232/233/282/283 - Cross-Site Request Forgery (Change Admin Password)
CVE-2014-1990webappshardware13 nov 2013
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Stu
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Altiris DS - SQL Injection (Metasploit)
CVE-2008-2286remotewindows13 nov 2013
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allow
50RIESGO
abrir
Exploit-DB
ALLPlayer 5.6.2 - '.m3u' File Local Buffer Overflow (SEH Unicode)
CVE-2013-7409localwindows12 nov 2013
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Exploit-DB
Juniper Junos J-Web - Privilege Escalation
CVE-2013-6618webappsphp12 nov 2013
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,
28RIESGO
abrir
Metasploit300
Red Hat CloudForms Management Engine 5.1 miq_policy/explorer SQL Injection
CVE-2013-205012 nov 2013
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and Mana
23RIESGO
abrir
Metasploit600
Kaseya uploadImage Arbitrary File Upload
CVE-2013-10034CRITICAL11 nov 2013
Kaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCE
63RIESGO
abrir
Metasploit300
Huawei Datacard Information Disclosure Vulnerability
CVE-2013-603111 nov 2013
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remot
18RIESGO
abrir
anteriorpágina 1123 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.