Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
CVE-2014-7146webappsmultiple18 nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir
Metasploit300
MS14-068 Microsoft Kerberos Checksum Validation Vulnerability
CVE-2014-6324HIGHbajo ataque18 nov 2014
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RIESGO
abrir
Metasploit300
Cisco DLSw Information Disclosure Scanner
CVE-2014-799217 nov 2014
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensiti
23RIESGO
abrir
Exploit-DB
Zoph 0.9.1 - Multiple Vulnerabilities
CVE-2014-9236webappsphp17 nov 2014
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier al
23RIESGO
abrir
Exploit-DB
Zoph 0.9.1 - Multiple Vulnerabilities
CVE-2014-9235webappsphp17 nov 2014
Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated
23RIESGO
abrir
Exploit-DB
WebsiteBaker 2.8.3 - Multiple Vulnerabilities
CVE-2014-9243webappsphp17 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DB
Maarch LetterBox 2.8 - (Authentication Bypass) Insecure Cookies
CVE-2014-8995webappsphp17 nov 2014
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the Us
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108L - Authentication Bypass (2)
CVE-2014-8493webappshardware17 nov 2014
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RIESGO
abrir
Exploit-DB
PHPFox - Persistent Cross-Site Scripting
CVE-2014-8469webappsphp17 nov 2014
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker
23RIESGO
abrir
Exploit-DB
.NET Remoting Services - Remote Command Execution
CVE-2014-1806remotewindows17 nov 2014
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not pr
35RIESGO
abrir
Exploit-DB
ZTE ZXHN H108L - Authentication Bypass (1)
CVE-2014-8493webappshardware17 nov 2014
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RIESGO
abrir
Exploit-DB
WebsiteBaker 2.8.3 - Multiple Vulnerabilities
CVE-2014-9242webappsphp17 nov 2014
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 5.1 Bypass) (MS12-037)
CVE-2012-1876remotewindows17 nov 2014
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir
Exploit-DB
Proticaret E-Commerce Script 3.0 - SQL Injection (2)
CVE-2014-9237webappsxml17 nov 2014
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a
23RIESGO
abrir
Exploit-DB
clientResponse Client Management 4.1 - Cross-Site Scripting
CVE-2014-100013webappsmultiple15 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in clientResponse 4.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DB
Gogs - 'users'/'repos' '?q' SQL Injection
CVE-2014-8682webappsmultiple14 nov 2014
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RIESGO
abrir
Exploit-DB
Gogs - 'label' SQL Injection
CVE-2014-8681webappsmultiple14 nov 2014
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
CVE-2014-6352HIGHbajo ataquelocalwindows14 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DBVexDay Proof
OSSEC 2.8 - 'hosts.deny' Local Privilege Escalation
CVE-2014-5284locallinux14 nov 2014
host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, whi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
CVE-2014-4114HIGHbajo ataquelocalwindows14 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-064) (Metasploit)
CVE-2014-6352HIGHbajo ataquelocalwindows14 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (via Python) (MS14-064) (Metasploit)
CVE-2014-4114HIGHbajo ataquelocalwindows14 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DB
MyBB 1.8.x - Multiple Vulnerabilities
CVE-2014-9241webappsphp13 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attack
23RIESGO
abrir
Metasploit400
MS14-064 Microsoft Internet Explorer Windows OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataque13 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Digi Online Examination System 2.0 - Unrestricted Arbitrary File Upload
CVE-2014-8997webappsphp13 nov 2014
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al
23RIESGO
abrir
Exploit-DB
MyBB 1.8.x - Multiple Vulnerabilities
CVE-2014-9240webappsphp13 nov 2014
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to ex
23RIESGO
abrir
Exploit-DB
Piwigo 2.6.0 - 'picture.php?rate' SQL Injection
CVE-2014-9115webappsphp13 nov 2014
SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x
23RIESGO
abrir
Exploit-DB
Proticaret E-Commerce Script 3.0 - SQL Injection (1)
CVE-2014-9237webappsmultiple13 nov 2014
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - OLE Automation Array Remote Code Execution (1)
CVE-2014-6332HIGHbajo ataqueremotewindows13 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
F5 BIG-IP 10.1.0 - Directory Traversal
CVE-2014-8727webappsjsp13 nov 2014
Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrat
23RIESGO
abrir
anteriorpágina 1076 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.