Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
Exploit-DBVexDay Proof
OSClass 3.4.1 - 'index.php' Local File Inclusion
CVE-2014-6308webappsphp25 sep 2014
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RIESGO
abrir
GitHub PoC2
CVE-2014-6271 RCE tool
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
Simple script to check for CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
woltage/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
CVE-2014-6271の検証用Vagrantfileです
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7196remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-3659remotelinux25 sep 2014
20RIESGO
abrir
GitHub PoC
mattclegg/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC1
scripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
Wordpress InfusionSoft Upload Vulnerability
CVE-2014-644625 sep 2014
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotecgi25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-62771remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-3671remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7169CRITICALbajo ataqueremotelinux25 sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7227remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-7227remotelinux25 sep 2014
20RIESGO
abrir
GitHub PoC
Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-3671remotecgi25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-7910remotelinux25 sep 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
GitHub PoC
a auto script to fix CVE-2014-6271 bash vulnerability
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC46
Python Scanner for "ShellShock" (CVE-2014-6271)
CVE-2014-6271CRITICALbajo ataque25 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Cart Engine 3.0 - Multiple Vulnerabilities
CVE-2014-8306webappsphp25 sep 2014
SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-7910remotecgi25 sep 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-7169CRITICALbajo ataqueremotelinux25 sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
Cart Engine 3.0 - Multiple Vulnerabilities
CVE-2014-8307webappsphp25 sep 2014
Multiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow
23RIESGO
abrir
Metasploit600
Pure-FTPd External Authentication Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
anteriorpágina 1087 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.