Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Exploit-DBVexDay Proof
Fonality trixbox - 'endpoint_generic.php' SQL Injection
CVE-2014-5109webappsphp17 jul 2014
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/affiliate_show_banner.php?affiliate_banner_id' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/affiliate_signup.php?a_country' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'endpointcfg.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'repo.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'asterisk_info.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RIESGO
abrir
Exploit-DBVexDay Proof
Fonality trixbox - 'index.php' Directory Traversal
CVE-2014-5111webappsphp17 jul 2014
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RIESGO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/admin/create_account.php?entry_country_id' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
OL-Commerce - '/OL-Commerce/create_account.php?country' SQL Injection
CVE-2014-5104webappsphp17 jul 2014
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Exploit-DBVexDay Proof
Alfresco - '/proxy?endpoint' Server-Side Request Forgery
CVE-2014-9301remotemultiple16 jul 2014
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Youtube Gallery 4.1.7 - SQL Injection
CVE-2014-4960webappsphp16 jul 2014
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x throu
23RIESGO
abrir
Exploit-DB
Boat Browser 8.0/8.0.1 - Remote Code Execution
CVE-2014-4968remoteandroid16 jul 2014
The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-022416 jul 2014
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph
60RIESGO
abrir
Exploit-DBVexDay Proof
Alfresco - '/cmisbrowser?url' Server-Side Request Forgery
CVE-2014-9302remotemultiple16 jul 2014
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Servi
23RIESGO
abrir
Exploit-DB
Node Browserify 4.2.0 - Remote Code Execution
CVE-2014-7192dosmultiple16 jul 2014
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rat
28RIESGO
abrir
Exploit-DB
BitDefender GravityZone 5.1.5.386 - Multiple Vulnerabilities
CVE-2014-5350webappslinux16 jul 2014
Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read
35RIESGO
abrir
Metasploit200
VirtualBox Guest Additions VBoxGuest.sys Privilege Escalation
CVE-2014-247715 jul 2014
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector Manager 8.10 - Remote Command Execution
CVE-2014-2623remotewindows14 jul 2014
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4965webappsphp14 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbit
23RIESGO
abrir
Exploit-DBVexDay Proof
Kolibri Web Server 2.0 - GET (SEH)
CVE-2014-4158remotewindows14 jul 2014
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RIESGO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4963webappsphp14 jul 2014
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.cu
23RIESGO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4964webappsphp14 jul 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijac
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link HNAP - Request Remote Buffer Overflow (Metasploit)
CVE-2014-3936remotehardware14 jul 2014
Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06
60RIESGO
abrir
Exploit-DB
Shopizer 1.1.5 - Multiple Vulnerabilities
CVE-2014-4962webappsphp14 jul 2014
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin DZS-VideoGallery - Cross-Site Scripting / Command Injection
CVE-2014-9094webappsphp13 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Vide
38RIESGO
abrir
Exploit-DB
OpenVPN Private Tunnel Core Service - Unquoted Service Path Privilege Escalation
CVE-2014-5455MEDIUMlocalwindows_x8612 jul 2014
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and Ope
33RIESGO
abrir
Exploit-DB
OpenVAS Manager 4.0 - Authentication Bypass
CVE-2013-6765remotelinux10 jul 2014
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restricti
23RIESGO
abrir
Exploit-DB
Infoblox 6.8.2.11 - OS Command Injection
CVE-2014-3418webappslinux_x8610 jul 2014
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via she
23RIESGO
abrir
Exploit-DBVexDay Proof
WeBid - Multiple Cross-Site Scripting / LDAP Injection Vulnerabilities
CVE-2014-5101webappsphp10 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin BSK PDF Manager - '/wp-admin/admin.php' Multiple SQL Injections
CVE-2014-4944webappsphp09 jul 2014
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress al
23RIESGO
abrir
anteriorpágina 1095 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.