Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Exploit-DB
F5 BIG-IQ 4.1.0.2013.0 - Privilege Escalation (Metasploit)
CVE-2014-2937remotehardware02 may 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0113remotemultiple02 may 2014
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict
45RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque01 may 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC18
Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque01 may 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Fritz!Box - Remote Command Execution
CVE-2014-9727webappshardware01 may 2014
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t
60RIESGO
abrir
Exploit-DB
Beetel 450TC2 Router - Cross-Site Request Forgery (Admin Password)
CVE-2014-3792webappshardware30 abr 2014
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote at
23RIESGO
abrir
Metasploit0
Cogent DataHub Command Injection
CVE-2014-378929 abr 2014
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Type Confusion Remote Code Execution (Metasploit)
CVE-2013-5331remotewindows29 abr 2014
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-3848webappsphp28 abr 2014
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-3849webappsphp28 abr 2014
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attac
23RIESGO
abrir
Exploit-DB
McAfee ePolicy Orchestrator 4.6.0 < 4.6.5 - 'ePowner' Multiple Vulnerabilities
CVE-2013-0140remotewindows28 abr 2014
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x b
23RIESGO
abrir
Exploit-DB
GeoCore MAX DB Ver. 7.3.3 - Blind SQL Injection
CVE-2006-3823webappsphp28 abr 2014
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic
23RIESGO
abrir
Exploit-DB
GeoCore MAX DB Ver. 7.3.3 - Blind SQL Injection
CVE-2014-3871webappsphp28 abr 2014
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-3842webappsphp28 abr 2014
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow
23RIESGO
abrir
Metasploit500
Adobe Flash Player Shader Buffer Overflow
CVE-2014-051528 abr 2014
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RIESGO
abrir
Metasploit300
Wireshark CAPWAP Dissector DoS
CVE-2013-407428 abr 2014
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.
50RIESGO
abrir
Metasploit500
Adobe Flash Player ByteArray UncompressViaZlibVariant Use After Free
CVE-2015-0311HIGHbajo ataque28 abr 2014
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 1.8.12/1.10.5 - wiretap/mpeg.c Stack Buffer Overflow (Metasploit)
CVE-2014-2299localwindows28 abr 2014
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-8948webappsphp28 abr 2014
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows re
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-8949webappsphp28 abr 2014
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitr
23RIESGO
abrir
Exploit-DB
NTP ntpd monlist Query Reflection - Denial of Service
CVE-2013-5211doslinux28 abr 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Exploit-DB
Symantec Endpoint Protection Manager 12.1.x - Overflow (SEH) (PoC)
CVE-2013-1612doswindows27 abr 2014
Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.
23RIESGO
abrir
GitHub PoC1
CVE-2014-0094 test program for struts1
CVE-2014-009427 abr 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
Exploit-DB
miSecureMessages 4.0.1 - Session Management / Authentication Bypass
CVE-2014-2347webappsmultiple25 abr 2014
AMTELCO miSecure Information Exposure
41RIESGO
abrir
Exploit-DBVexDay Proof
Kolibri Web Server 2.0 - GET Stack Buffer Overflow
CVE-2014-4158remotewindows25 abr 2014
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RIESGO
abrir
Exploit-DB
Acunetix 8 build 20120704 - Remote Stack Overflow
CVE-2014-2994remotewindows24 abr 2014
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RIESGO
abrir
Exploit-DB
WD Arkeia Virtual Appliance 10.2.9 - Local File Inclusion
CVE-2014-2846webappsphp24 abr 2014
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmw
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0346remotemultiple24 abr 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0160HIGHbajo ataqueremotemultiple24 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
dompdf 0.6.0 - 'dompdf.php?read' Arbitrary File Read
CVE-2014-2383webappsphp24 abr 2014
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RIESGO
abrir
anteriorpágina 1104 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.