Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
Metasploit300
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit300
Qmail SMTP Bash Environment Variable Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6278HIGHbajo ataque24 sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Metasploit300
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
CVE-2014-6278HIGHbajo ataque24 sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Exploit-DBVexDay Proof
EMC AlphaStor Device Manager Opcode 0x75 - Command Injection (Metasploit)
CVE-2013-0928remotewindows24 sep 2014
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir
Metasploit0
Mac OS X IOKit Keyboard Driver Root Privilege Escalation
CVE-2014-4404HIGHbajo ataque24 sep 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RIESGO
abrir
Metasploit300
OS X VMWare Fusion Privilege Escalation via Bash Environment Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit300
DHCP Client Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
Dhclient Bash Environment Variable Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6278HIGHbajo ataque24 sep 2014
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Exploit-DB
Restaurant Script (PizzaInn Project) - Persistent Cross-Site Scripting
CVE-2014-6619webappsphp24 sep 2014
Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 a
23RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Webaccess - dvs.ocx GetColor Buffer Overflow (Metasploit)
CVE-2014-2364remotewindows24 sep 2014
Advantech WebAccess Stack-Based Buffer Overflow
68RIESGO
abrir
Exploit-DB
webEdition 6.3.8.0 (SVN-Revision: 6985) - Directory Traversal
CVE-2014-5258webappsphp24 sep 2014
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated
43RIESGO
abrir
GitHub PoC
Collected fixes for bash CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
patched-bash-4.3 for CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC6
Patch for CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque24 sep 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit500
Adobe Flash Player copyPixelsToByteArray Method Integer Overflow
CVE-2014-055623 sep 2014
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS
60RIESGO
abrir
Exploit-DBVexDay Proof
LittleSite 0.1 - 'index.php' Local File Inclusion
CVE-2009-3542webappsphp23 sep 2014
Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to incl
23RIESGO
abrir
Exploit-DB
M/Monit 3.3.2 - Cross-Site Request Forgery
CVE-2014-6607webappsphp20 sep 2014
M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers
23RIESGO
abrir
GitHub PoC46
Research of CVE-2014-3153 and its famous exploit towelroot on x86
CVE-2014-3153HIGHbajo ataque20 sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
Exploit-DB
M/Monit 3.3.2 - Cross-Site Request Forgery
CVE-2014-6409webappsphp20 sep 2014
Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authe
23RIESGO
abrir
Exploit-DB
Livefyre LiveComments Plugin - Persistent Cross-Site Scripting
CVE-2014-6420webappsphp20 sep 2014
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHbajo ataque20 sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
Exploit-DB
ClassApps SelectSurvey.net - Multiple SQL Injections
CVE-2014-6030webappsphp20 sep 2014
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
CVE-2014-5460webappsphp16 sep 2014
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Routers - '/cgi-bin/AZ_Retrain.cgi' Denial of Service
CVE-2014-6435doshardware15 sep 2014
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
28RIESGO
abrir
Exploit-DB
CacheGuard-OS 5.7.7 - Cross-Site Request Forgery
CVE-2014-4865webappslinux15 sep 2014
Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
CVE-2014-6287CRITICALbajo ataqueremotewindows15 sep 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
anteriorpágina 1088 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.