Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DB
Watchguard Firewall XTM 11.7.4u1 - Remote Buffer Overflow
CVE-2013-6021remotehardware29 oct 2013
Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code
28RIESGO
abrir
Exploit-DBVexDay Proof
Olat CMS 7.8.0.1 - Persistent Cross-Site Scripting
CVE-2013-6793webappsphp29 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote a
23RIESGO
abrir
Exploit-DBVexDay Proof
BlazeDVD 6.2 - '.plf' Local Buffer Overflow (SEH)
CVE-2006-6199localwindows28 oct 2013
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir
Metasploit300
VideoCharge Studio Buffer Overflow (SEH)
CVE-2025-34123HIGH27 oct 2013
VideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC File
36RIESGO
abrir
Exploit-DBVexDay Proof
Poppler 0.14.3 - '/utils/pdfseparate.cc' Local Format String
CVE-2013-4474locallinux26 oct 2013
Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote
28RIESGO
abrir
Exploit-DBVexDay Proof
Open Flash Chart 2 - Arbitrary File Upload (Metasploit)
CVE-2011-4275remotephp26 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RIESGO
abrir
Exploit-DBVexDay Proof
Open Flash Chart 2 - Arbitrary File Upload (Metasploit)
CVE-2009-4140remotephp26 oct 2013
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RIESGO
abrir
Metasploit600
ProcessMaker Open Source Authenticated PHP Code Execution
CVE-2013-10035HIGH24 oct 2013
ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution
36RIESGO
abrir
Metasploit600
VICIdial Manager Send OS Command Injection
CVE-2013-446723 oct 2013
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RIESGO
abrir
Metasploit600
VICIdial Manager Send OS Command Injection
CVE-2013-446823 oct 2013
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RIESGO
abrir
Exploit-DBVexDay Proof
HP Intelligent Management Center BIms UploadServlet - Directory Traversal (Metasploit)
CVE-2013-4822remotewindows22 oct 2013
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
50RIESGO
abrir
Exploit-DBVexDay Proof
Interactive Graphical SCADA System - Remote Command Injection (Metasploit)
CVE-2011-1566remotewindows22 oct 2013
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Shindig - XML External Entity Information Disclosure
CVE-2013-4295remotemultiple21 oct 2013
The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML d
28RIESGO
abrir
Exploit-DBVexDay Proof
ZonPHP 2.25 - Remote Code Execution
CVE-2009-4140webappsphp20 oct 2013
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RIESGO
abrir
Exploit-DBVexDay Proof
ZonPHP 2.25 - Remote Code Execution
CVE-2011-4275webappsphp20 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RIESGO
abrir
Metasploit300
Node.js HTTP Pipelining Denial of Service
CVE-2013-445018 oct 2013
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of se
30RIESGO
abrir
Metasploit600
WebTester 5.x Command Execution
CVE-2013-10037CRITICAL17 oct 2013
WebTester 5.x install2.php Unauthenticated Command Execution
68RIESGO
abrir
Exploit-DBVexDay Proof
Oracle GlassFish Server 2.1.1/3.0.1 - Multiple Subcomponent Resource Identifier Traversal Arbitrary File Access
CVE-2013-3827remotemultiple15 oct 2013
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2;
50RIESGO
abrir
Exploit-DB
Apple iOS 7.0.2 - Sim Lock Screen Display Bypass
CVE-2013-5147webappsios15 oct 2013
Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers
23RIESGO
abrir
Exploit-DB
Zabbix 2.0.8 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2013-5743webappsunix15 oct 2013
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
60RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector - Cell Request Service Buffer Overflow (Metasploit)
CVE-2013-2333remotewindows15 oct 2013
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arb
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2013-3893HIGHbajo ataque15 oct 2013
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CDisplayPointer Use-After-Free (MS13-080) (Metasploit)
CVE-2013-3897HIGHbajo ataqueremotewindows15 oct 2013
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo
100RIESGO
abrir
Exploit-DBVexDay Proof
VMware Hyperic HQ Groovy Script-Console - Java Execution (Metasploit)
CVE-2013-6366remotemultiple14 oct 2013
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link / PLANEX COMMUNICATIONS - 'RuntimeDiagnosticPing()' Remote Stack Buffer Overflow
CVE-2013-6027remotehardware14 oct 2013
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow rem
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Cart66 1.5.1.14 - Multiple Vulnerabilities
CVE-2013-5977webappsphp14 oct 2013
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP
23RIESGO
abrir
Exploit-DB
Android Zygote - Socket and Fork Bomb (Denial of Service)
CVE-2011-3918dosandroid14 oct 2013
The Zygote process in Android 4.0.3 and earlier accepts fork requests from processes with arbitrary UIDs, which allows r
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Cart66 1.5.1.14 - Multiple Vulnerabilities
CVE-2013-5978webappsphp14 oct 2013
Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPr
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 4.1.x - '/install/upgrade.php' Security Bypass
CVE-2013-6129webappsphp13 oct 2013
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the
50RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet FortiAnalyzer - Cross-Site Request Forgery
CVE-2013-6826remotehardware12 oct 2013
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate th
23RIESGO
abrir
anteriorpágina 1126 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.