Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Metasploit300
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Authentication Bypass
CVE-2014-922217 dic 2014
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re
30RIESGO
abrir
GitHub PoC3
CVE-2014-0196: Linux kernel pty layer race condition memory corruption
CVE-2014-0196MEDIUMbajo ataque17 dic 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
VulnCheck XDB
local
CVE-2014-0196MEDIUMbajo ataque17 dic 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
Exploit-DBVexDay Proof
Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Code Execution (Metasploit)
CVE-2014-4936localwindows16 dic 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir
Exploit-DB
CMS Papoo 6.0.0 Rev. 4701 - Persistent Cross-Site Scripting
CVE-2014-9522webappsphp16 dic 2014
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject
23RIESGO
abrir
Metasploit400
Malwarebytes Anti-Malware and Anti-Exploit Update Remote Code Execution
CVE-2014-493616 dic 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir
Metasploit600
Symantec Web Gateway 5 restore.php Post Authentication Command Injection
CVE-2014-728516 dic 2014
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir
Metasploit600
ManageEngine Multiple Products Authenticated File Upload
CVE-2014-530115 dic 2014
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir
Exploit-DB
phpMyAdmin 4.0.x/4.1.x/4.2.x - Denial of Service
CVE-2014-9218dosphp15 dic 2014
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows re
28RIESGO
abrir
Exploit-DB
GLPI 0.85 - Blind SQL Injection
CVE-2014-9258webappsphp15 dic 2014
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec
23RIESGO
abrir
Exploit-DB
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload
CVE-2014-10021webappsphp15 dic 2014
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir
Exploit-DBVexDay Proof
Tuleap - PHP Unserialize Code Execution (Metasploit)
CVE-2014-8791remotephp15 dic 2014
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RIESGO
abrir
GitHub PoC2
NTP monlist scanner CVE-2013-5211
CVE-2013-521114 dic 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Exploit-DB
IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution
CVE-2015-0104webappsjsp12 dic 2014
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database
23RIESGO
abrir
Exploit-DB
IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution
CVE-2015-0107webappsjsp12 dic 2014
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database
23RIESGO
abrir
Metasploit600
WordPress WP Symposium 14.11 Shell Upload
CVE-2014-1002111 dic 2014
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir
Exploit-DB
Humhub 0.10.0-rc.1 - SQL Injection
CVE-2014-9528webappsphp10 dic 2014
SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListControlle
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenEMR 4.1.2(7) - Multiple SQL Injections
CVE-2014-5462webappsphp10 dic 2014
Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execut
23RIESGO
abrir
Exploit-DB
WordPress Plugin Symposium 14.10 - SQL Injection
CVE-2014-8810webappsphp09 dic 2014
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo
23RIESGO
abrir
Exploit-DB
Advantech AdamView 4.30.003 - '.gni' Local Buffer Overflow (SEH)
CVE-2014-8386localwindows09 dic 2014
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
Metasploit300
BMC TrackIt! Unauthenticated Arbitrary User Password Change
CVE-2014-827009 dic 2014
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose na
23RIESGO
abrir
Metasploit600
Lexmark MarkVision Enterprise Arbitrary File Upload
CVE-2014-874109 dic 2014
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RIESGO
abrir
Exploit-DB
PBBoard CMS 3.0.1 - SQL Injection
CVE-2014-9215webappsphp05 dic 2014
SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Privilege Escalation (MS14-068)
CVE-2014-6324HIGHbajo ataqueremotewindows05 dic 2014
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RIESGO
abrir
Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
CVE-2014-9142webappshardware04 dic 2014
Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers t
23RIESGO
abrir
Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
CVE-2014-9144webappshardware04 dic 2014
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac
23RIESGO
abrir
Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
CVE-2014-9143webappshardware04 dic 2014
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect us
23RIESGO
abrir
Exploit-DB
Advertise With Pleasure! (AWP) 6.6 - SQL Injection
CVE-2014-9345webappscgi04 dic 2014
SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows r
23RIESGO
abrir
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5445webappsmultiple03 dic 2014
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir
Exploit-DB
BulletProof FTP Client 2010 - Local Buffer Overflow (SEH)
CVE-2014-2973localwindows03 dic 2014
35RIESGO
abrir
anteriorpágina 1073 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.