Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.927exploits catalogados
37.571CVEs con explotación pública
24.695probados en laboratorio
80.927 exploits
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-7227webappscgi01 oct 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-3671webappscgi01 oct 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
CVE-2014-3659webappscgi01 oct 2014
20RIESGO
abrir
Metasploit300
MS15-001 Microsoft Windows NtApphelpCacheControl Improper Authorization Check
CVE-2015-000230 sep 2014
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,
43RIESGO
abrir
Metasploit600
IPFire Bash Environment Variable Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque29 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 5.0 Bypass) (MS12-037)
CVE-2012-1876remotewindows29 sep 2014
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir
Metasploit600
Joomla Akeeba Kickstart Unserialize Remote Code Execution
CVE-2014-722829 sep 2014
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RIESGO
abrir
GitHub PoC2
CVE-2014-6271 Remote Interactive Shell - PoC Exploit
CVE-2014-6271CRITICALbajo ataque29 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-7169CRITICALbajo ataqueremotelinux29 sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-7187remotelinux29 sep 2014
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers t
35RIESGO
abrir
GitHub PoC1
ryeyao/CVE-2014-6271_Test
CVE-2014-6271CRITICALbajo ataque29 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC13
shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI
CVE-2014-6271CRITICALbajo ataque29 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-6278HIGHbajo ataqueremotelinux29 sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-7186remotelinux29 sep 2014
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial o
35RIESGO
abrir
GitHub PoC
This module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible
CVE-2014-6271CRITICALbajo ataque29 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
OpenFiler 2.99.1 - Cross-Site Request Forgery
CVE-2014-7190webappsphp29 sep 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the auth
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque29 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
dhclient 4.1 - Bash Environment Variable Command Injection (Shellshock)
CVE-2014-6277remotelinux29 sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque28 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque28 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)
CVE-2014-6271CRITICALbajo ataque28 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC12
A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server
CVE-2014-6271CRITICALbajo ataque28 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
ManageEngine OpManager and Social IT Arbitrary File Upload
CVE-2014-603427 sep 2014
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in Z
60RIESGO
abrir
Exploit-DB
Typo3 Extension JobControl 2.14.0 - Cross-Site Scripting / SQL Injection
CVE-2014-7201webappsphp27 sep 2014
Multiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (d
23RIESGO
abrir
Exploit-DB
dbPowerAmp < 2.0/10.0 - Local Buffer Overflow
CVE-2004-1569localwindows27 sep 2014
Buffer overflow in (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe in dBpowerAMP Audio Player 2.0 and dbPowerA
23RIESGO
abrir
GitHub PoC
u20024804/bash-4.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Typo3 Extension JobControl 2.14.0 - Cross-Site Scripting / SQL Injection
CVE-2014-7200webappsphp27 sep 2014
Cross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extensi
23RIESGO
abrir
GitHub PoC
u20024804/bash-4.3-fixed-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
u20024804/bash-3.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
anteriorpágina 1085 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.