Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Exploit-DB
Linux Kernel 3.14-rc1 < 3.15-rc4 (x64) - Raw Mode PTY Echo Race Condition Privilege Escalation
CVE-2014-0196MEDIUMbajo ataquelocallinux_x86-6426 may 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
Exploit-DBVexDay Proof
dpkg Source Package - Index: pseudo-header Processing Multiple Local Directory Traversals
CVE-2014-3865locallinux25 may 2014
Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files out
23RIESGO
abrir
Exploit-DBVexDay Proof
User Cake - Cross-Site Request Forgery
CVE-2014-3866webappsphp25 may 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remo
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 'Submit_News' Component - SQL Injection
CVE-2014-3934webappsphp24 may 2014
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Mayan-EDms Web-Based Document Management OS System - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2014-3840webappsmultiple24 may 2014
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.1
23RIESGO
abrir
Metasploit300
Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow
CVE-2014-388823 may 2014
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RIESGO
abrir
Exploit-DBVexDay Proof
Pyplate - 'addScript.py' Cross-Site Request Forgery
CVE-2014-3854webappspython23 may 2014
Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack
23RIESGO
abrir
Metasploit300
D-Link info.cgi POST Request Buffer Overflow
CVE-2014-125117CRITICAL22 may 2014
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RIESGO
abrir
GitHub PoC12
A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team
CVE-2014-011422 may 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache mod_wsgi - Information Disclosure
CVE-2014-0242remotelinux21 may 2014
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive info
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Booking System (Booking Calendar) - 'booking_form_id' SQL Injection
CVE-2014-3210webappsphp21 may 2014
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for Wo
23RIESGO
abrir
Metasploit300
Easy File Management Web Server Stack Buffer Overflow
CVE-2014-379120 may 2014
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Exploit-DBVexDay Proof
SafeNet Sentinel Protection Server 7.0 < 7.4 / Sentinel Keys Server 1.0.3 < 1.0.4 - Directory Traversal
CVE-2007-6483webappswindows19 may 2014
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier version
28RIESGO
abrir
Exploit-DB
HP Release Control - (Authenticated) XML External Entity (Metasploit)
CVE-2014-2612webappswindows19 may 2014
Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x b
23RIESGO
abrir
Exploit-DB
SPIP CMS < 2.0.23/ 2.1.22/3.0.9 - Privilege Escalation
CVE-2013-2118webappsphp19 may 2014
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "ta
23RIESGO
abrir
Exploit-DBVexDay Proof
XOOPS Glossaire Module - '/modules/glossaire/glossaire-aff.php' SQL Injection
CVE-2014-3935webappsphp19 may 2014
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut
23RIESGO
abrir
Exploit-DBVexDay Proof
Winamp - '.flv' File Processing Memory Corruption
CVE-2014-3442doswindows16 may 2014
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor
23RIESGO
abrir
Exploit-DBVexDay Proof
CIS Manager - 'email' SQL Injection
CVE-2014-3749webappsasp16 may 2014
SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DB
eGroupWare 1.8.006 - Multiple Vulnerabilities
CVE-2014-2987webappsphp16 may 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in EGroupware Enterprise Line (EPL) before 1.1.20140505, EGro
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 1.10.7 - Denial of Service (PoC)
CVE-2014-5116doswindows16 may 2014
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attac
23RIESGO
abrir
Exploit-DBVexDay Proof
RealPlayer - '.3gp' File Processing Memory Corruption
CVE-2014-3444dosmultiple16 may 2014
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to exec
23RIESGO
abrir
Metasploit300
D-Link HNAP Request Remote Buffer Overflow
CVE-2014-393615 may 2014
Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06
60RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2014-3120HIGHbajo ataquewebappsmultiple15 may 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
Exploit-DBVexDay Proof
Easy File Sharing Web Server 6.8 - Remote Stack Buffer Overflow
CVE-2014-3791remotewindows14 may 2014
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Exploit-DBVexDay Proof
Broadcom PIPA C211 - Sensitive Information Disclosure
CVE-2014-2046webappshardware14 may 2014
cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allow
23RIESGO
abrir
VulnCheck XDB
local
CVE-2014-0196MEDIUMbajo ataque13 may 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
GitHub PoC
Demonstration of CVE-2014-3120
CVE-2014-3120HIGHbajo ataque13 may 2014
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
GitHub PoC
SunRain/CVE-2014-0196
CVE-2014-0196MEDIUMbajo ataque13 may 2014
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir
Exploit-DB
Skybox Security 6.3.x < 6.4.x - Multiple Information Disclosures
CVE-2014-2084webappshardware12 may 2014
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RIESGO
abrir
Exploit-DBVexDay Proof
SpiceWorks 7.2.00174 - Persistent Cross-Site Scripting
CVE-2014-3740webappswindows12 may 2014
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RIESGO
abrir
anteriorpágina 1102 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.