Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5445webappsmultiple03 dic 2014
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir
Exploit-DB
WordPress Plugin Cart66 Lite eCommerce 1.5.1.17 - Blind SQL Injection
CVE-2014-9305webappsphp03 dic 2014
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RIESGO
abrir
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5446webappsmultiple03 dic 2014
Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2
35RIESGO
abrir
Exploit-DB
WordPress Plugin Nextend Facebook Connect 1.4.59 - Cross-Site Scripting
CVE-2014-8800webappsphp02 dic 2014
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before
23RIESGO
abrir
Exploit-DB
EntryPass N5200 - Credentials Exposure
CVE-2014-9303webappshardware02 dic 2014
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator
23RIESGO
abrir
Exploit-DB
tnftp (FreeBSD 8/9/10) - 'tnftp' Client Side
CVE-2014-8517remotebsd02 dic 2014
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro
50RIESGO
abrir
Exploit-DB
Thomson Reuters Fixed Assets CS 13.1.4 - Local Privilege Escalation
CVE-2014-9141localwindows02 dic 2014
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which all
23RIESGO
abrir
Exploit-DBVexDay Proof
Tincd - (Authenticated) Remote TCP Stack Buffer Overflow (Metasploit)
CVE-2013-1428remotemultiple02 dic 2014
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RIESGO
abrir
Exploit-DB
ProjectSend r-561 - Arbitrary File Upload
CVE-2014-9567webappsphp02 dic 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)
CVE-2014-4404HIGHbajo ataquelocalosx02 dic 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RIESGO
abrir
Exploit-DB
EntryPass N5200 - Credentials Exposure
CVE-2014-8868webappshardware02 dic 2014
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain
23RIESGO
abrir
Exploit-DB
TYPO3 Extension ke DomPDF - Remote Code Execution
CVE-2014-6235webappsphp02 dic 2014
Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary
23RIESGO
abrir
Metasploit600
ProjectSend Arbitrary File Upload
CVE-2014-956702 dic 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir
Exploit-DB
WordPress Core < 4.0.1 - Denial of Service
CVE-2014-9034dosphp01 dic 2014
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all
45RIESGO
abrir
GitHub PoC13
Python scripts to exploit CVE-2014-9016 and CVE-2014-9034
CVE-2014-901601 dic 2014
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
Exploit-DB
Drupal < 7.34 - Denial of Service
CVE-2014-9016dosphp01 dic 2014
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
Exploit-DB
WordPress Core 4.0 - Denial of Service
CVE-2014-9034dosphp01 dic 2014
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all
45RIESGO
abrir
Metasploit300
ManageEngine NetFlow Analyzer Arbitrary File Download
CVE-2014-544530 nov 2014
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir
GitHub PoC5
app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data Add token fiddling from nishang 12 hours ago db Revert "Diff triggering comment" 12 days ago documentation Switch to Msf::OperatingSystems::Match::WINDOWS 2 months ago external Use PDWORD_PTR and DWORD_PTR 29 days ago features Up aruba timeout for simplecov overhead 4 days ago lib Check for load errors in reload_all 4 days ago modules Land #4255 - CVE-2014-6332 Internet Explorer 19 hours ago plugins Land #3588, @tobd-r7's Fix SpaceBeforeModifierKeyword Rubocop warning 4 months ago script rails generate cucumber:install 3 months ago scripts delete the old script a month ago spec Remove debug file writes 2 days ago test Fix up comment splats with the correct URI a month ago tools Fix bugs 24 days ago .gitignore Add note about rbenv for rvm .versions.conf local override 24 days ago .gitmodules Add RDI submodule, port Kitrap0d a year ago .mailmap Add @trosen-r7's alias for commits 6 months ago .rspec Add modern --require to .rspec 2 months ago .rubocop.yml Reapply PR #4113 (removed via #4175) 18 days ago .ruby-gemset Restoring ruby and gemset files 6 months ago .ruby-version Oh good, another Ruby version bump 14 days ago .simplecov Remove fastlib 2 months ago .travis.yml Enable fast_finish on travis-ci 12 days ago .yardopts Various merge resolutions from master <- staging 4 months ago CONTRIBUTING.md Add a don't to CONTRIBUTING about merge messages 11 days ago COPYING With 66 days left in 2014, may as well update a month ago Gemfile metasploit-credential bump to 0.13.3 16 days ago Gemfile.local.example Various merge resolutions from master <- staging 4 months ago Gemfile.lock Bump mdm version number 12 days ago HACKING Update link for The Metasploit Development Environment 5 months ago LICENSE Remove fastlib 2 months ago README.md Encourage use of the installer for users. 8 months ago Rakefile Merge branch 'feature/MSP-11130/metasploit-framework-spec-constants' … 24 days ago metasploit-framework-db.gemspec metasploit-credential bump to 0.13.3 16 days ago metasploit-framework-full.gemspec Update metasploit-framework-full.gemspec 23 days ago metasploit-framework-pcap.gemspec Depend on metasloit-framework in optional gemspecs 24 days ago metasploit-framework.gemspec Update meterpreter_bins to 0.0.11 18 days ago msfbinscan Remove fastlib 2 months ago msfcli Fix thread-leaks in msfcli spec 17 days ago msfconsole @wvu-r7 is a skilled negotiator. s/stdout/stderr/ a month ago msfd Remove fastlib 2 months ago msfelfscan Remove fastlib 2 months ago msfencode Remove fastlib 2 months ago msfmachscan Remove fastlib 2 months ago msfpayload fixes merge conflicts msfpayload & exe a month ago msfpescan Remove fastlib 2 months ago msfrop Remove fastlib 2 months ago msfrpc Remove fastlib 2 months ago msfrpcd Remove call to legacy db.sink queue, closes #4244 7 days ago msfupdate Always use maybe_wait_and_exit in msfupdate a year ago msfvenom Fix #4047 - undefined method `rank' due to an invalid encoder name 19 days ago README.md
CVE-2014-6332HIGHbajo ataque29 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
CCH Wolters Kluwer PFX Engagement 7.1 - Local Privilege Escalation
CVE-2014-9113localwindows28 nov 2014
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RIESGO
abrir
Metasploit600
Tuleap PHP Unserialize Code Execution
CVE-2014-879127 nov 2014
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RIESGO
abrir
GitHub PoC9
Spydir is a small utility to monitor file changes in Windows directory regardless of subdirectory and files permissions (exploits CVE-2007-0843)
CVE-2007-084327 nov 2014
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions
23RIESGO
abrir
Metasploit600
WordPress RevSlider File Upload and Execute Vulnerability
CVE-2014-973526 nov 2014
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RIESGO
abrir
Exploit-DB
Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 - '.wax' Local Buffer Overflow (SEH)
CVE-2014-9448localwindows26 nov 2014
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RIESGO
abrir
Exploit-DB
Elipse E3 - HTTP Denial of Service
CVE-2014-8652doswindows26 nov 2014
Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via
23RIESGO
abrir
Exploit-DB
Android WAPPushManager - SQL Injection
CVE-2014-8507dosandroid26 nov 2014
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin DB Backup - Arbitrary File Download
CVE-2014-9119webappsphp26 nov 2014
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at
43RIESGO
abrir
Exploit-DB
xEpan 1.0.1 - Cross-Site Request Forgery
CVE-2014-8429webappsphp26 nov 2014
Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows
23RIESGO
abrir
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8424webappshardware25 nov 2014
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio
50RIESGO
abrir
Exploit-DB
Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
CVE-2014-3153HIGHbajo ataquelocallinux25 nov 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
anteriorpágina 1074 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.