Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Exploit-DBVexDay Proof
Digi Online Examination System 2.0 - Unrestricted Arbitrary File Upload
CVE-2014-8997webappsphp13 nov 2014
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 al
23RIESGO
abrir
Exploit-DB
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
CVE-2014-6352HIGHbajo ataquelocalwindows12 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DB
Microsoft Office 2007/2010 - OLE Arbitrary Command Execution
CVE-2014-4114HIGHbajo ataquelocalwindows12 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Metasploit600
MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python
CVE-2014-6352HIGHbajo ataque12 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DB
WordPress Plugin SupportEzzy Ticket System 1.2.5 - Persistent Cross-Site Scripting
CVE-2014-9179webappsphp12 nov 2014
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe
23RIESGO
abrir
Metasploit200
MS14-070 Windows tcpip!SetAddrOptions NULL Pointer Dereference
CVE-2014-407611 nov 2014
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Metasploit600
WordPress Photo Gallery Unrestricted File Upload
CVE-2014-931211 nov 2014
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RIESGO
abrir
Metasploit400
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
CVE-2014-844011 nov 2014
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RIESGO
abrir
Exploit-DB
WordPress Plugin Photo Gallery 1.2.5 - Unrestricted Arbitrary File Upload
CVE-2014-9312webappsphp11 nov 2014
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RIESGO
abrir
Exploit-DB
Subex Fms 7.4 - SQL Injection
CVE-2014-8728webappsmultiple11 nov 2014
SQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System a
23RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7868webappsjsp10 nov 2014
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT
45RIESGO
abrir
Exploit-DBVexDay Proof
Visual Mining NetCharts Server - Remote Code Execution (Metasploit)
CVE-2014-8516remotejava10 nov 2014
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co
60RIESGO
abrir
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8607webappsphp10 nov 2014
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command lin
23RIESGO
abrir
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8603webappsphp10 nov 2014
cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9004webappsphp10 nov 2014
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DB
Password Manager Pro / Pro MSP - Blind SQL Injection
CVE-2014-8499webappsmultiple10 nov 2014
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Servi
50RIESGO
abrir
Exploit-DB
PHP-Fusion 7.02.07 - SQL Injection
CVE-2014-8596webappsphp10 nov 2014
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8604webappsphp10 nov 2014
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th
23RIESGO
abrir
Exploit-DBVexDay Proof
phpSound Music Sharing Platform 1.0.5 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2014-8954webappsphp10 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
Exploit-DB
Password Manager Pro / Pro MSP - Blind SQL Injection
CVE-2014-8498webappsmultiple10 nov 2014
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager P
28RIESGO
abrir
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8606webappsphp10 nov 2014
Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administ
23RIESGO
abrir
Exploit-DB
WordPress Plugin / Joomla! Component XCloner - Multiple Vulnerabilities
CVE-2014-8605webappsphp10 nov 2014
The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under t
23RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7866webappsjsp10 nov 2014
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and
45RIESGO
abrir
Exploit-DBVexDay Proof
vldPersonals 2.7 - Multiple Vulnerabilities
CVE-2014-9005webappsphp10 nov 2014
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DB
WordPress Plugin Another WordPress Classifieds Plugin - SQL Injection
CVE-2014-10013webappsphp10 nov 2014
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to
23RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7868webappsmultiple09 nov 2014
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT
45RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-6036webappsmultiple09 nov 2014
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Socia
35RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-6034webappsmultiple09 nov 2014
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in Z
60RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-7866webappsmultiple09 nov 2014
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and
45RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Social IT Plus / IT360 - Multiple Vulnerabilities
CVE-2014-6035webappsmultiple09 nov 2014
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier al
28RIESGO
abrir
anteriorpágina 1077 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.