Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
GitHub PoC
u20024804/bash-4.3-fixed-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
u20024804/bash-3.2-fixed-CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque27 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
An A/V evasion armoring experiment for CVE-2012-4681
CVE-2012-4681CRITICALbajo ataqueransomware26 sep 2014
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque26 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
local
CVE-2012-4681CRITICALbajo ataqueransomware26 sep 2014
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir
GitHub PoC4
CVE-2014-6271 (ShellShock) RCE PoC tool
CVE-2014-6271CRITICALbajo ataque26 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
scaner for cve-2014-6271
CVE-2014-6271CRITICALbajo ataque26 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
Salt recipe for shellshock (CVE-2014-6271)
CVE-2014-6271CRITICALbajo ataque26 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Ansible role to check the CVE-2014-6271 vulnerability
CVE-2014-6271CRITICALbajo ataque26 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)
CVE-2014-6271CRITICALbajo ataque26 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-7910remotecgi25 sep 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-62771remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-3671remotecgi25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotecgi25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-3671remotelinux25 sep 2014
20RIESGO
abrir
GitHub PoC
Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7169CRITICALbajo ataqueremotelinux25 sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
GitHub PoC46
Python Scanner for "ShellShock" (CVE-2014-6271)
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
a auto script to fix CVE-2014-6271 bash vulnerability
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Cart Engine 3.0 - Multiple Vulnerabilities
CVE-2014-8307webappsphp25 sep 2014
Multiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-6271CRITICALbajo ataqueremotelinux25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
WordPress Plugin All In One WP Security 3.8.2 - SQL Injection
CVE-2014-6242webappsphp25 sep 2014
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RIESGO
abrir
GitHub PoC
mattclegg/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7196remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
OSClass 3.4.1 - 'index.php' Local File Inclusion
CVE-2014-6308webappsphp25 sep 2014
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-3671remotelinux25 sep 2014
20RIESGO
abrir
anteriorpágina 1086 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.