Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Metasploit300
ManageEngine Password Manager SQLAdvancedALSearchResult.cc Pro SQL Injection
CVE-2014-849908 nov 2014
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Servi
50RIESGO
abrir
Metasploit500
MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
CVE-2014-859808 nov 2014
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RIESGO
abrir
Metasploit500
MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
CVE-2014-714608 nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir
GitHub PoC1
CVE-2000-0170
CVE-2000-017008 nov 2014
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variabl
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque06 nov 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Belkin N750 - 'jump?login' Remote Buffer Overflow
CVE-2014-1635remotehardware06 nov 2014
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RIESGO
abrir
Exploit-DBVexDay Proof
X7 Chat 2.0.5 - 'message.php' PHP Code Execution (Metasploit)
CVE-2014-8998remotephp06 nov 2014
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a c
50RIESGO
abrir
Metasploit300
i-FTP Schedule Buffer Overflow
CVE-2014-125114HIGH06 nov 2014
i-Ftp 2.20 Schedule.xml Stack-Based Buffer Overflow
36RIESGO
abrir
Exploit-DB
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
CVE-2014-3437webappsjsp06 nov 2014
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read ar
23RIESGO
abrir
Exploit-DB
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
CVE-2014-3438webappsjsp06 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager
23RIESGO
abrir
Exploit-DB
Symantec Endpoint Protection 12.1.4023.4080 - Multiple Vulnerabilities
CVE-2014-3439webappsjsp06 nov 2014
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Citrix Netscaler SOAP Handler - Remote Code Execution (Metasploit)
CVE-2014-7140remotebsd06 nov 2014
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetS
28RIESGO
abrir
GitHub PoC2
:scream: Python library and utility for CVE-2014-6271 (aka. "shellshock")
CVE-2014-6271CRITICALbajo ataque06 nov 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
CVE-2014-8775webappsphp05 nov 2014
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, whic
23RIESGO
abrir
Exploit-DB
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
CVE-2014-8773webappsphp05 nov 2014
MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mec
23RIESGO
abrir
Exploit-DB
MODx CMS 2.2.14 - Cross-Site Request Forgery Bypass / Reflected Cross-Site Scripting / Persistent Cross-Site Scripting
CVE-2014-8774webappsphp05 nov 2014
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attacke
23RIESGO
abrir
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (2)
CVE-2014-6039webappsmultiple05 nov 2014
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio
50RIESGO
abrir
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (2)
CVE-2014-6038webappsmultiple05 nov 2014
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili
60RIESGO
abrir
Metasploit300
ManageEngine Eventlog Analyzer Managed Hosts Administrator Credential Disclosure
CVE-2014-603805 nov 2014
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili
60RIESGO
abrir
Metasploit300
ManageEngine Eventlog Analyzer Managed Hosts Administrator Credential Disclosure
CVE-2014-603905 nov 2014
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio
50RIESGO
abrir
Metasploit600
Visual Mining NetCharts Server Remote Code Execution
CVE-2014-851603 nov 2014
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary co
60RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-3671webappsphp03 nov 2014
20RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-6271CRITICALbajo ataquewebappsphp03 nov 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
CVE-2014-3704webappsphp03 nov 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-62771webappsphp03 nov 2014
20RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7227webappsphp03 nov 2014
20RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7196webappsphp03 nov 2014
20RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7910webappsphp03 nov 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DB
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session)
CVE-2014-3704webappsphp03 nov 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-3659webappsphp03 nov 2014
20RIESGO
abrir
anteriorpágina 1078 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.