Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Dell KACE K1000 File Upload
CVE-2014-125113CRITICAL07 mar 2014
Dell/Quest KACE K1000 Unauthenticated File Upload RCE
43RIESGO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-011406 mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-009406 mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-011206 mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir
Metasploit0
Vtiger Install Unauthenticated Remote Command Execution
CVE-2014-226805 mar 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RIESGO
abrir
Metasploit300
Joomla weblinks-categories Unauthenticated SQL Injection Arbitrary File Read
CVE-2014-798102 mar 2014
SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL
18RIESGO
abrir
Metasploit300
Oracle Demantra Database Credentials Leak
CVE-2013-588028 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir
Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
CVE-2013-587728 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir
Metasploit300
Oracle Demantra Database Credentials Leak
CVE-2013-579528 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir
Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
CVE-2013-588028 feb 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir
Metasploit300
MantisBT Admin SQL Injection Arbitrary File Read
CVE-2014-223828 feb 2014
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 a
23RIESGO
abrir
Metasploit300
JIRA Issues Collector Directory Traversal
CVE-2014-231426 feb 2014
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager /servlet/ConsoleServlet Remote Command Execution
CVE-2013-501424 feb 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager /servlet/ConsoleServlet Remote Command Execution
CVE-2013-501524 feb 2014
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RIESGO
abrir
Metasploit400
SolidWorks Workgroup PDM 2014 pdmwService.exe Arbitrary File Write
CVE-2014-10001522 feb 2014
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir
Metasploit300
Linksys WRT120N tmUnblock Stack Buffer Overflow
CVE-2014-125122MEDIUM19 feb 2014
Linksys WRT120N tmUnblock.cgi Stack-Based Buffer Overflow Admin Password Reset
28RIESGO
abrir
Metasploit600
Linksys E-Series TheMoon Remote Command Injection
CVE-2025-34037CRITICAL13 feb 2014
Linksys Routers E/WAG/WAP/WES/WET/WRT-Series
85RIESGO
abrir
Metasploit300
MS14-012 Microsoft Internet Explorer CMarkup Use-After-Free
CVE-2014-0322HIGHbajo ataque13 feb 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Metasploit600
Fritz!Box Webcm Unauthenticated Command Injection
CVE-2014-972711 feb 2014
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t
60RIESGO
abrir
Metasploit500
MS14-009 .NET Deployment Service IE Sandbox Escape
CVE-2014-025711 feb 2014
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RIESGO
abrir
Metasploit300
Apache Commons FileUpload and Apache Tomcat DoS
CVE-2014-005006 feb 2014
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir
Metasploit300
Adobe Flash Player Integer Underflow Remote Code Execution
CVE-2014-0497HIGHbajo ataque05 feb 2014
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RIESGO
abrir
Metasploit300
Publish-It PUI Buffer Overflow (SEH)
CVE-2014-098005 feb 2014
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Metasploit600
Array Networks vAPV and vxAG Private Key Privilege Escalation Code Execution
CVE-2014-125121CRITICAL03 feb 2014
Array Networks vAPV and vxAG Default Credential Privilege Escalation
43RIESGO
abrir
Metasploit400
Linux Kernel recvmmsg Privilege Escalation
CVE-2014-003802 feb 2014
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Metasploit600
Pandora FMS Default Credential / SQLi Remote Code Execution
CVE-2014-125115CRITICAL01 feb 2014
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RIESGO
abrir
Metasploit600
Zpanel Remote Unauthenticated RCE
CVE-2013-209730 ene 2014
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir
Metasploit600
Pandora FMS Remote Code Execution
CVE-2014-125124CRITICAL29 ene 2014
Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection
63RIESGO
abrir
Metasploit600
MediaWiki Thumb.php Remote Command Execution
CVE-2014-161028 ene 2014
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir
Metasploit300
A10 Networks AX Loadbalancer Directory Traversal
CVE-2014-125125HIGH28 ene 2014
A10 Networks AX Loadbalancer Path Traversal
36RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.