Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
VulnCheck XDB
local
CVE-2013-2094HIGHbajo ataque29 mar 2015
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
GitHub PoC4
CVE-2015-0235 EXIM ESTMP GHOST Glibc Gethostbyname() DoS Exploit/PoC
CVE-2015-023528 mar 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
WebGate Control Center 4.8.7 - GetThumbnail Stack Overflow
CVE-2015-2099remotewindows27 mar 2015
Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vec
28RIESGO
abrir
Exploit-DB
Berta CMS - Arbitrary File Upload
CVE-2015-2780webappsphp27 mar 2015
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a cra
28RIESGO
abrir
Exploit-DBVexDay Proof
Acunetix 9.5 - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows27 mar 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
WebGate eDVR Manager 2.6.4 - SiteName Stack Overflow
CVE-2015-2098remotewindows27 mar 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir
Exploit-DB
WebGate WinRDS 2.0.8 - StopSiteAllChannel Stack Overflow
CVE-2015-2094remotewindows27 mar 2015
Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to
28RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DB
RM Downloader 2.7.5.400 - Local Buffer Overflow
CVE-2009-1646localwindows26 mar 2015
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 mar 2015
20RIESGO
abrir
GitHub PoC3
Spider Exploit with CVE-2013-2842
CVE-2013-284226 mar 2015
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service o
28RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
CVE-2015-2097remotewindows26 mar 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
CVE-2015-2295webappsphp26 mar 2015
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9013webappsphp25 mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9014webappsphp25 mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir
Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
CVE-2015-0313HIGHbajo ataqueremotewindows25 mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir
anteriorpágina 1060 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.