Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Metasploit300
OpenSSL DTLS Fragment Buffer Overflow DoS
CVE-2014-019505 jun 2014
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0
40RIESGO
abrir
Metasploit300
OpenSSL Server-Side ChangeCipherSpec Injection Scanner
CVE-2014-022405 jun 2014
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph
60RIESGO
abrir
Exploit-DBVexDay Proof
Foreman Smart-Proxy - Remote Command Injection
CVE-2014-0007remotemultiple05 jun 2014
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via
23RIESGO
abrir
Metasploit0
Chkrootkit Local Privilege Escalation
CVE-2014-047604 jun 2014
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir
Exploit-DB
IPSwitch IMail Server WEB client 12.4 - Persistent Cross-Site Scripting
CVE-2014-3878webappswindows03 jun 2014
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4,
23RIESGO
abrir
Exploit-DB
WordPress Plugin Participants Database 1.5.4.8 - SQL Injection
CVE-2014-3961webappsphp02 jun 2014
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo
23RIESGO
abrir
Metasploit300
Ericom AccessNow Server Buffer Overflow
CVE-2014-391302 jun 2014
Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrar
50RIESGO
abrir
Exploit-DB
dbus-glib pam_fprintd - Local Privilege Escalation
CVE-2013-0292locallinux02 jun 2014
The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.2.0-23/3.5.0-23 (Ubuntu 12.04/12.04.1/12.04.2 x64) - 'perf_swevent_init' Local Privilege Escalation (3)
CVE-2013-2094HIGHbajo ataquelocallinux_x86-6431 may 2014
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch Dynamic Script - Arbitrary Java Execution (Metasploit)
CVE-2014-3120HIGHbajo ataqueremotejava30 may 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
Exploit-DBVexDay Proof
Huawei E303 Router - Cross-Site Request Forgery
CVE-2014-2946remotehardware30 may 2014
Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin ENL NewsLetter - '/wp-admin/admin.php' SQL Injection
CVE-2014-4939webappsphp28 may 2014
SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticate
23RIESGO
abrir
Exploit-DB
Sharetronix 3.3 - Multiple Vulnerabilities
CVE-2014-3414webappsphp28 may 2014
Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authenti
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Tera Charts (tera-charts) - '/charts/zoomabletreemap.php?fn' Directory Traversal
CVE-2014-4940webappsphp28 may 2014
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attacker
43RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP Rss Poster - '/wp-admin/admin.php' SQL Injection
CVE-2014-4938webappsphp28 may 2014
SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Tera Charts (tera-charts) - '/charts/treemap.php?fn' Directory Traversal
CVE-2014-4940webappsphp28 may 2014
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attacker
43RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark CAPWAP Dissector - Denial of Service (Metasploit)
CVE-2013-4074dosmultiple28 may 2014
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin BookX 1.7 - 'bookx_export.php' Local File Inclusion
CVE-2014-4937webappsphp28 may 2014
Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to
23RIESGO
abrir
Exploit-DB
Sharetronix 3.3 - Multiple Vulnerabilities
CVE-2014-3415webappsphp28 may 2014
SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
AuraCMS 3.0 - Multiple Vulnerabilities
CVE-2014-3975webappsphp28 may 2014
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via
23RIESGO
abrir
Exploit-DBVexDay Proof
AuraCMS 3.0 - Multiple Vulnerabilities
CVE-2014-3974webappsphp28 may 2014
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject
23RIESGO
abrir
Exploit-DB
TORQUE Resource Manager 2.5.x < 2.5.13 - Stack Buffer Overflow Stub
CVE-2014-0749remotelinux28 may 2014
Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Reso
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin HDW Player - '/wp-admin/admin.php' SQL Injection
CVE-2014-5180webappsphp28 may 2014
SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 fo
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.3.5 - '/drivers/media/media-device.c' Local Information Disclosure
CVE-2014-1739locallinux28 may 2014
The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initi
23RIESGO
abrir
Exploit-DBVexDay Proof
webEdition CMS - 'we_fs.php' SQL Injection
CVE-2014-2303webappsphp28 may 2014
Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and
23RIESGO
abrir
Exploit-DBVexDay Proof
Easy File Sharing FTP Server 3.5 - Remote Stack Buffer Overflow
CVE-2006-3952remotewindows27 may 2014
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RIESGO
abrir
Exploit-DBVexDay Proof
Castor Library - XML External Entity Information Disclosure
CVE-2014-3004remotemultiple27 may 2014
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct
23RIESGO
abrir
Exploit-DB
ZYXEL P-660HW-T1 3 Wireless Router - Cross-Site Request Forgery
CVE-2014-4162webappshardware26 may 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote att
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.14-rc1 < 3.15-rc4 (x64) - Raw Mode PTY Echo Race Condition Privilege Escalation
CVE-2014-0196MEDIUMbajo ataquelocallinux_x86-6426 may 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
Exploit-DBVexDay Proof
Videos Tube 1.0 - Multiple SQL Injections
CVE-2014-3962webappsphp26 may 2014
Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
anteriorpágina 1101 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.