Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Exploit-DB
PHPMyRecipes 1.2.2 - 'dosearch.php?words_exact' SQL Injection
CVE-2014-9347webappsphp25 nov 2014
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DB
TRENDnet SecurView Wireless Network Camera TV-IP422WN - 'UltraCamX.ocx' Stack Buffer Overflow (PoC)
CVE-2014-10011doswindows25 nov 2014
Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView ca
28RIESGO
abrir
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8425webappshardware25 nov 2014
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the confi
23RIESGO
abrir
Metasploit300
Arris VAP2500 tools_command.php Command Execution
CVE-2014-842425 nov 2014
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio
50RIESGO
abrir
Metasploit300
Arris VAP2500 tools_command.php Command Execution
CVE-2014-842325 nov 2014
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir
Metasploit300
Adobe Flash Player PCRE Regex Vulnerability
CVE-2015-031825 nov 2014
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8423webappshardware25 nov 2014
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir
Exploit-DB
WordPress Plugin Google Document Embedder 2.5.14 - SQL Injection
CVE-2014-9173webappsphp25 nov 2014
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)
CVE-2014-4880remotelinux24 nov 2014
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir
Exploit-DB
RobotStats 1.0 - 'robot' SQL Injection
CVE-2014-9348webappsphp24 nov 2014
SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Advantech EKI-6340 - Command Injection
CVE-2014-8387webappscgi24 nov 2014
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar
35RIESGO
abrir
Exploit-DB
WordPress Plugin Download Manager 2.7.2 - Privilege Escalation
CVE-2014-9260webappsphp24 nov 2014
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users
28RIESGO
abrir
Exploit-DB
TP-Link TL-WR740N - Denial of Service
CVE-2014-9350doshardware24 nov 2014
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RIESGO
abrir
Exploit-DB
Microsoft Windows 8.1/ Server 2012 - 'Win32k.sys' Local Privilege Escalation (MS14-058)
CVE-2014-4113HIGHbajo ataquelocalwindows24 nov 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DB
RobotStats 1.0 - HTML Injection
CVE-2014-9349dosaix24 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RIESGO
abrir
Exploit-DB
WordPress Plugin wpDataTables 1.5.3 - SQL Injection
CVE-2014-9175webappsphp24 nov 2014
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote
23RIESGO
abrir
Exploit-DB
WordPress Plugin DukaPress 2.5.2 - Directory Traversal
CVE-2014-8799webappsphp24 nov 2014
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir
Exploit-DB
tcpdump 4.6.2 - Geonet Decoder Denial of Service
CVE-2014-8768dosmultiple24 nov 2014
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow rem
28RIESGO
abrir
Exploit-DB
WordPress Plugin CM Download Manager 2.0.0 - Code Injection
CVE-2014-8877webappsphp22 nov 2014
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SP Client Document Manager 2.4.1 - SQL Injection
CVE-2014-9178webappsphp21 nov 2014
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu
23RIESGO
abrir
Exploit-DB
FluxBB < 1.5.6 - SQL Injection
CVE-2014-10029webappsmultiple21 nov 2014
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to exe
23RIESGO
abrir
Metasploit300
WordPress Long Password DoS
CVE-2014-901620 nov 2014
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
CVE-2014-6332HIGHbajo ataqueremotewindows20 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Metasploit500
HP Performance Monitoring xglance Priv Esc
CVE-2014-263019 nov 2014
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RIESGO
abrir
GitHub PoC3
PowerShell CVE-2014-4113
CVE-2014-4113HIGHbajo ataque19 nov 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Metasploit300
Hikvision DVR RTSP Request Remote Code Execution
CVE-2014-488019 nov 2014
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Paid Memberships Pro 1.7.14.2 - Directory Traversal
CVE-2014-8801webappsphp19 nov 2014
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress
28RIESGO
abrir
Exploit-DB
Snowfox CMS 1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2014-9344webappsphp19 nov 2014
Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authe
23RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (2)
CVE-2014-7146remotephp18 nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
CVE-2014-8598webappsmultiple18 nov 2014
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RIESGO
abrir
anteriorpágina 1075 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.