Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
SolidWorks Workgroup PDM 2014 SP2 Opcode 2001 - Denial of Service
CVE-2014-100014doswindows19 feb 2014
Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Dassault Systemes Catia - Remote Stack Buffer Overflow
CVE-2014-2072remotemultiple19 feb 2014
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
23RIESGO
abrir
Exploit-DB
Open Web Analytics 1.5.4 - 'owa_email_address' SQL Injection
CVE-2014-1206webappsphp18 feb 2014
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (1)
CVE-2013-5019remotewindows18 feb 2014
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Forms and Reports - Remote Code Execution (Metasploit)
CVE-2012-3152CRITICALbajo ataqueremotewindows18 feb 2014
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir
Exploit-DBVexDay Proof
i-doit Pro - 'objID' SQL Injection
CVE-2014-1597webappsphp17 feb 2014
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remot
23RIESGO
abrir
Exploit-DB
HP Data Protector - 'EXEC_BAR' Remote Command Execution
CVE-2013-2347remotewindows16 feb 2014
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DB
ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH)
CVE-2014-1947localwindows16 feb 2014
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote
23RIESGO
abrir
Exploit-DB
ImageMagick 6.8.8-4 - Local Buffer Overflow (SEH)
CVE-2014-2030localwindows16 feb 2014
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remot
28RIESGO
abrir
Exploit-DBVexDay Proof
Eudora Qualcomm WorldMail 9.0.333.0 - IMAPd Service UID Buffer Overflow
CVE-2014-10031remotewindows16 feb 2014
Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DB
CA 2E Web Option 8.1.2 - Authentication Bypass
CVE-2014-1219webappsmultiple13 feb 2014
CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy CD-DA Recorder - '.pls' Local Buffer Overflow (Metasploit)
CVE-2010-2343localwindows13 feb 2014
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbi
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Commons FileUpload and Apache Tomcat - Denial of Service
CVE-2014-0050dosmultiple12 feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir
Exploit-DBVexDay Proof
KingScada - kxClientDownload.ocx ActiveX Remote Code Execution (Metasploit)
CVE-2013-2827remotewindows11 feb 2014
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir
Exploit-DB
WordPress Plugin BuddyPress 1.9.1 - Privilege Escalation
CVE-2014-1889webappsphp11 feb 2014
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain
28RIESGO
abrir
Exploit-DB
Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation
CVE-2013-6282HIGHbajo ataquelocalarm11 feb 2014
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenuEx Win32k NULL Page (MS13-081) (Metasploit)
CVE-2013-3881localwindows11 feb 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RIESGO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1842webappswindows11 feb 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1843webappswindows11 feb 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Exploit-DB
Titan FTP Server 10.32 Build 1816 - Directory Traversal
CVE-2014-1841webappswindows11 feb 2014
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Exploit-DBVexDay Proof
Tableau Server < 8.0.7 / < 8.1.2 - Blind SQL Injection
CVE-2014-1204webappswindows11 feb 2014
SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated user
23RIESGO
abrir
Exploit-DB
ZTE ZXV10 W300 Router - Hard-Coded Credentials
CVE-2014-0329webappshardware09 feb 2014
The TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account
23RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - '.pui' Local Buffer Overflow (SEH)
CVE-2014-0980localwindows08 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DB
CTERA 3.2.29.0/3.2.42.0 - Persistent Cross-Site Scripting
CVE-2013-2639webappsphp07 feb 2014
Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
osCommerce 2.3.3.4 - 'geo_zones.php?zID' SQL Injection
CVE-2014-10033webappsphp07 feb 2014
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RIESGO
abrir
Exploit-DB
doorGets CMS 5.2 - SQL Injection
CVE-2014-1459webappsphp07 feb 2014
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RIESGO
abrir
Exploit-DBVexDay Proof
Android Browser and WebView addJavascriptInterface - Code Execution (Metasploit)
CVE-2013-4710remotehardware07 feb 2014
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir
Exploit-DB
AuraCMS 2.3 - Multiple Vulnerabilities
CVE-2014-1401webappsphp07 feb 2014
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - Buffer Overflow
CVE-2014-0980doswindows06 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
CVE-2013-7052webappshardware05 feb 2014
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
28RIESGO
abrir
anteriorpágina 235 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.