Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
80.930 exploits
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
CVE-2014-6287CRITICALbajo ataqueremotewindows15 sep 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Eventlog Analyzer - Arbitrary File Upload (Metasploit)
CVE-2014-6037remotemultiple15 sep 2014
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Modem Routers - Session Hijacking
CVE-2014-6436remotehardware15 sep 2014
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
Railo 4.2.1 - Remote File Inclusion (Metasploit)
CVE-2014-5468remotemultiple15 sep 2014
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
50RIESGO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHbajo ataque13 sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC19
CVE-2014-3153 exploit
CVE-2014-3153HIGHbajo ataque13 sep 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
Metasploit600
Phpwiki Ploticus Remote Code Execution
CVE-2014-551911 sep 2014
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev
50RIESGO
abrir
Metasploit600
Rejetto HttpFileServer Remote Command Execution
CVE-2014-6287CRITICALbajo ataque11 sep 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
Metasploit300
MS14-052 Microsoft Internet Explorer XMLDOM Filename Disclosure
CVE-2013-7331MEDIUMbajo ataque09 sep 2014
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the exist
70RIESGO
abrir
Metasploit300
HP Network Node Manager I PMD Buffer Overflow
CVE-2014-262409 sep 2014
Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute ar
50RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central StatusUpdate - Arbitrary File Upload (Metasploit)
CVE-2014-5006remotewindows09 sep 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central StatusUpdate - Arbitrary File Upload (Metasploit)
CVE-2014-5005remotewindows09 sep 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6045webappsphp08 sep 2014
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6046webappsphp08 sep 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th
23RIESGO
abrir
Exploit-DB
Mpay24 PrestaShop Payment Module 1.5 - Multiple Vulnerabilities
CVE-2014-2009webappsphp08 sep 2014
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6047webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6050webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6048webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6049webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins
23RIESGO
abrir
Exploit-DB
Mpay24 PrestaShop Payment Module 1.5 - Multiple Vulnerabilities
CVE-2014-2008webappsphp08 sep 2014
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RIESGO
abrir
Exploit-DB
PhpOnlineChat 3.0 - Cross-Site Scripting
CVE-2014-100017webappsphp07 sep 2014
Cross-site scripting (XSS) vulnerability in canned_opr.php in PhpOnlineChat 3.0 allows remote attackers to inject arbitr
23RIESGO
abrir
GitHub PoC15
Scans NTP servers for CVE-2013-5211 NTP DDOS amplification vulnerability.
CVE-2013-521107 sep 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Exploit-DB
LoadedCommerce7 - Systemic Query Factory
CVE-2014-5140webappsphp07 sep 2014
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha
23RIESGO
abrir
Exploit-DBVexDay Proof
BulletProof FTP Client 2010 - Buffer Overflow (SEH)
CVE-2014-2973doswindows05 sep 2014
35RIESGO
abrir
Exploit-DB
WordPress Plugin Huge-IT Image Gallery 1.0.1 - (Authenticated) SQL Injection
CVE-2014-7153webappsphp02 sep 2014
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 9.0.1 / Thunderbird 3.1.20 - Information Disclosure
CVE-2014-1564remotemultiple02 sep 2014
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize m
23RIESGO
abrir
Exploit-DB
Syslog LogAnalyzer 3.6.5 - Persistent Cross-Site Scripting
CVE-2014-6070webappsmultiple02 sep 2014
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RIESGO
abrir
Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
CVE-2013-7390webappsjsp01 sep 2014
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (1)
CVE-2014-6037webappsjsp01 sep 2014
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir
Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (1)
CVE-2014-6043webappsjsp01 sep 2014
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database
28RIESGO
abrir
anteriorpágina 1089 / 2698siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.