Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Exploit-DBVexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
CVE-2014-4971localwindows_x8615 oct 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Metasploit600
Centreon SQL and Command Injection
CVE-2014-382915 oct 2014
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RIESGO
abrir
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3828webappslinux15 oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir
Metasploit600
Centreon SQL and Command Injection
CVE-2014-382815 oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir
Metasploit600
Drupal HTTP Parameter Key/Value SQL Injection
CVE-2014-370415 oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3829webappslinux15 oct 2014
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RIESGO
abrir
Exploit-DBVexDay Proof
YourMembers Plugin - Blind SQL Injection
CVE-2014-100003webappsphp14 oct 2014
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RIESGO
abrir
Exploit-DB
Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2014-8577webappsphp14 oct 2014
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DB
Tenda A32 Router - Cross-Site Request Forgery
CVE-2014-7281webappshardware14 oct 2014
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RIESGO
abrir
Metasploit300
SSL/TLS Version Detection
CVE-2014-3566LOW14 oct 2014
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which mak
45RIESGO
abrir
Metasploit300
Windows TrackPopupMenu Win32k NULL Pointer Dereference
CVE-2014-4113HIGHbajo ataque14 oct 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Metasploit600
MS14-060 Microsoft Windows OLE Package Manager Code Execution
CVE-2014-4114HIGHbajo ataque14 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Metasploit300
SSL/TLS Version Detection
CVE-2013-2566MEDIUM14 oct 2014
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for
50RIESGO
abrir
Metasploit300
SSL/TLS Version Detection
CVE-2011-338914 oct 2014
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefo
40RIESGO
abrir
Metasploit500
Adobe Flash Player casi32 Integer Overflow
CVE-2014-056914 oct 2014
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and bef
60RIESGO
abrir
Metasploit300
SSL/TLS Version Detection
CVE-2016-080014 oct 2014
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to se
40RIESGO
abrir
Metasploit300
SSL/TLS Version Detection
CVE-2022-335814 oct 2014
Using a Custom Cipher with NID_undef may lead to NULL encryption
18RIESGO
abrir
Metasploit300
SSL/TLS Version Detection
CVE-2015-4000LOW14 oct 2014
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not pro
45RIESGO
abrir
GitHub PoC10
Exploit for CVE-2014-7236
CVE-2014-723612 oct 2014
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DB
CMS Made Simple 1.11.9 - Multiple Vulnerabilities
CVE-2014-0334webappsphp12 oct 2014
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitr
23RIESGO
abrir
Exploit-DB
GetSimple CMS 3.3.1 - Cross-Site Scripting
CVE-2014-1603webappsphp12 oct 2014
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DB
Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities
CVE-2014-2921webappshardware12 oct 2014
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 doe
23RIESGO
abrir
Exploit-DB
Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities
CVE-2014-2922webappshardware12 oct 2014
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 doe
23RIESGO
abrir
Exploit-DB
vBulletin 4.x/5.x - AdminCP/ApiLog via xmlrpc API (Authenticated) Persistent Cross-Site Scripting
CVE-2014-2021webappsphp12 oct 2014
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a
23RIESGO
abrir
Exploit-DB
vBulletin 4.x - breadcrumbs via xmlrpc API (Authenticated) SQL Injection
CVE-2014-2022webappsphp12 oct 2014
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a
23RIESGO
abrir
GitHub PoC1
Heartbleed (CVE-2014-0160) SSLv3 Scanner
CVE-2014-0160HIGHbajo ataque12 oct 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
BMC Track-It! - Multiple Vulnerabilities
CVE-2014-4874webappswindows09 oct 2014
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin InfusionSoft - Arbitrary File Upload (Metasploit)
CVE-2014-6446remotephp09 oct 2014
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows
50RIESGO
abrir
Exploit-DBVexDay Proof
Nessus Web UI 2.3.3 - Persistent Cross-Site Scripting
CVE-2014-7280webappsmultiple09 oct 2014
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web s
23RIESGO
abrir
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) - Remote Command Execution (Metasploit)
CVE-2014-6287CRITICALbajo ataqueremotewindows09 oct 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
anteriorpágina 1081 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.