Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Metasploit600
AlienVault OSSIM SQL Injection and Remote Code Execution
CVE-2016-858124 abr 2014
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RIESGO
abrir
Exploit-DB
HP Laser Jet - JavaScript Persistent Cross-Site Scripting via PJL Directory Traversal
CVE-2010-4107webappshardware23 abr 2014
The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printer
28RIESGO
abrir
Exploit-DB
Sixnet Sixview 2.4.1 - Web Console Directory Traversal
CVE-2014-2976webappshardware22 abr 2014
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Local Security Bypass
CVE-2014-1322localosx22 abr 2014
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RIESGO
abrir
Exploit-DB
kitForm CRM Extension 0.43 - 'sorter.ph?sorter_value' SQL Injection
CVE-2014-3757webappsphp22 abr 2014
SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (K
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0633remotewindows21 abr 2014
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10
28RIESGO
abrir
Metasploit600
Oracle Event Processing FileUploadServlet Arbitrary File Upload
CVE-2014-242421 abr 2014
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0634remotewindows21 abr 2014
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x
60RIESGO
abrir
Exploit-DB
Teracom Modem T2-B-Gawv1.4U10Y-BI - Cross-Site Request Forgery
CVE-2014-10019webappshardware20 abr 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Ga
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque19 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC4
openssl Heartbleed bug(CVE-2014-0160) check for Node.js
CVE-2014-0160HIGHbajo ataque19 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
NRPE 2.15 - Remote Command Execution
CVE-2014-2913remotemultiple18 abr 2014
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote atta
28RIESGO
abrir
Exploit-DB
Linux Kernel - 'group_info' refcounter Overflow Memory Corruption
CVE-2014-2851doslinux18 abr 2014
Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP Router - Timing Attack Password Disclosure
CVE-2014-0984remotehardware17 abr 2014
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation
23RIESGO
abrir
Exploit-DBVexDay Proof
Jzip - Buffer Overflow (PoC) (SEH Unicode)
CVE-2010-5300doswindows16 abr 2014
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CMarkup Use-After-Free (MS14-012) (Metasploit)
CVE-2014-0322HIGHbajo ataqueremotewindows16 abr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Exploit-DB
Xerox DocuShare - SQL Injection
CVE-2014-3138webappshardware15 abr 2014
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Unitrends Enterprise Backup 7.3.0 - Root Remote Code Execution (Metasploit)
CVE-2014-3008remoteunix15 abr 2014
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte
23RIESGO
abrir
Exploit-DB
Unitrends Enterprise Backup 7.3.0 - Root Remote Code Execution (Metasploit)
CVE-2014-3139remoteunix15 abr 2014
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Reader for Android 11.1.3 - Arbitrary JavaScript Execution
CVE-2014-0514localandroid15 abr 2014
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RIESGO
abrir
Exploit-DBVexDay Proof
lxml - 'clean_html' Security Bypass
CVE-2014-3146MEDIUMremotelinux15 abr 2014
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct
33RIESGO
abrir
GitHub PoC3
A checker (site and tool) for CVE-2014-0160
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
A checker (site and tool) for CVE-2014-0160:
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC98
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.
CVE-2014-0160HIGHbajo ataque15 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/MGConfigData' Multiple Directory Traversals
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/Installer?file' Directory Traversal
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 10 - CMarkup Use-After-Free (MS14-012)
CVE-2014-0322HIGHbajo ataqueremotewindows14 abr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Exploit-DB
WordPress Plugin Twitget 3.3.1 - Multiple Vulnerabilities
CVE-2014-2995webappsphp14 abr 2014
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RIESGO
abrir
Metasploit500
Adobe Flash Player domainMemory ByteArray Use After Free
CVE-2015-035914 abr 2014
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RIESGO
abrir
anteriorpágina 1105 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.