Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Exploit-DB
ntopng 1.2.0 - Cross-Site Scripting Injection
CVE-2014-5464webappsmultiple26 ago 2014
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Password Manager - MetadataServlet.dat SQL Injection (Metasploit)
CVE-2014-3996webappsmultiple25 ago 2014
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central
50RIESGO
abrir
Exploit-DB
Innovaphone PBX Admin-GUI - Cross-Site Request Forgery
CVE-2014-5335webappsmultiple25 ago 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attack
23RIESGO
abrir
Metasploit300
NTP Mode 6 UNSETTRAP DRDoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
NTP Mode 6 REQ_NONCE DRDoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
NTP Mode 7 PEER_LIST_SUM DoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
NTP Mode 7 GET_RESTRICT DRDoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
Netcore Router Udp 53413 Backdoor
CVE-2025-34117CRITICAL25 ago 2014
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RIESGO
abrir
Metasploit300
NTP Mode 7 PEER_LIST DoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Exploit-DB
LiveWorld Multiple Products - Cross Site Scripting
CVE-2004-2566webappsasp23 ago 2014
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Password Manager Pro / ManageEngine IT360 - SQL Injection
CVE-2014-3997webappsmultiple20 ago 2014
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manag
28RIESGO
abrir
Exploit-DBVexDay Proof
ArticleFR - 'id' SQL Injection
CVE-2014-5097webappsphp20 ago 2014
Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - toString console.time Privileged JavaScript Injection (Metasploit)
CVE-2013-1670remotemultiple19 ago 2014
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbi
28RIESGO
abrir
VulnCheck XDB
client-side
CVE-2013-1690HIGHbajo ataque19 ago 2014
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP Content Source Control - 'download.php' Directory Traversal
CVE-2014-5368webappsphp19 ago 2014
Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Sour
43RIESGO
abrir
GitHub PoC15
Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)
CVE-2013-1690HIGHbajo ataque19 ago 2014
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before
98RIESGO
abrir
Metasploit600
SolarWinds Storage Manager Authentication Bypass
CVE-2015-537119 ago 2014
The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scr
40RIESGO
abrir
Exploit-DBVexDay Proof
Gitlab-shell - Code Execution (Metasploit)
CVE-2013-4490remotelinux19 ago 2014
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x
50RIESGO
abrir
Exploit-DB
Tenda A5s Router 3.02.05_CN - Authentication Bypass
CVE-2014-5246webappshardware18 ago 2014
The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication
28RIESGO
abrir
Exploit-DB
Alienvault Open Source SIEM (OSSIM) < 4.7.0 - 'get_license' Remote Command Execution (Metasploit)
CVE-2014-5210remotelinux14 ago 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
28RIESGO
abrir
Exploit-DB
WordPress Plugin Disqus 2.7.5 - Cross-Site Request Forgery (Admin Persistent) / Cross-Site Scripting
CVE-2014-5347webappsphp14 ago 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 4.3.6 - 3D Acceleration Virtual Machine Escape (Metasploit)
CVE-2015-4523remotewindows_x86-6414 ago 2014
Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtu
23RIESGO
abrir
Exploit-DB
WordPress Plugin Disqus 2.7.5 - Cross-Site Request Forgery (Admin Persistent) / Cross-Site Scripting
CVE-2014-5345webappsphp14 ago 2014
Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress al
23RIESGO
abrir
Exploit-DB
WordPress Plugin Disqus 2.7.5 - Cross-Site Request Forgery (Admin Persistent) / Cross-Site Scripting
CVE-2014-5346webappsphp14 ago 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow
23RIESGO
abrir
Exploit-DB
VMTurbo Operations Manager 4.6 - 'vmtadmin.cgi' Remote Command Execution (Metasploit)
CVE-2014-5073remotelinux14 ago 2014
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 4.3.6 - 3D Acceleration Virtual Machine Escape (Metasploit)
CVE-2014-0983remotewindows_x86-6414 ago 2014
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox Guest Additions 4.3.10r93012 - 'VBoxGuest.sys' Local Privilege Escalation (Metasploit)
CVE-2014-2477localwindows13 ago 2014
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin GB Gallery Slideshow - '/wp-admin/admin-ajax.php' SQL Injection
CVE-2014-8375webappsphp11 ago 2014
SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administ
23RIESGO
abrir
Metasploit300
Yokogawa BKBCopyD.exe Client
CVE-2014-520809 ago 2014
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00
23RIESGO
abrir
Exploit-DB
TomatoCart 1.x - SQL Injection
CVE-2014-3978webappsphp09 ago 2014
SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands
23RIESGO
abrir
anteriorpágina 1092 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.