Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
81.003 exploits
Exploit-DBVexDay Proof
Xangati - '/servlet/MGConfigData' Multiple Directory Traversals
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
Exploit-DB
WordPress Plugin Twitget 3.3.1 - Multiple Vulnerabilities
CVE-2014-2995webappsphp14 abr 2014
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/Installer?file' Directory Traversal
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
GitHub PoC
Test script for test 1Password database for SSL Hea(r)t Bleeding (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
CubeCart 5.2.8 - Session Fixation
CVE-2014-2341webappsphp13 abr 2014
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID
23RIESGO
abrir
Metasploit400
Adobe Reader for Android addJavascriptInterface Exploit
CVE-2014-051413 abr 2014
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.
CVE-2014-0160HIGHbajo ataque13 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC5
POC for CVE-2014-0160 (Heartbleed) for DTLS
CVE-2014-0160HIGHbajo ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC6
Script to find Exit and Guard nodes in the Tor Network, that are still suffering from CVE-2014-0160
CVE-2014-0160HIGHbajo ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque12 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Sendy 1.1.9.1 - SQL Injection
CVE-2014-100011webappsphp11 abr 2014
SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
GitHub PoC2
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.
CVE-2014-0160HIGHbajo ataque11 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
CVE-2014-0160 scanner
CVE-2014-0160HIGHbajo ataque11 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
XCloner Standalone 3.5 - Cross-Site Request Forgery
CVE-2014-2996webappsphp10 abr 2014
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administr
23RIESGO
abrir
GitHub PoC2
This repo contains a script to automatically test sites for vulnerability to the Heartbleed Bug (CVE-2014-0160) based on the input file for the urls.
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
CVE-2014-0346remotemultiple10 abr 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
CVE-2014-0160HIGHbajo ataqueremotemultiple10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
CVE-2014-1761HIGHbajo ataquelocalwindows10 abr 2014
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2849remoteunix10 abr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RIESGO
abrir
Exploit-DBVexDay Proof
Vtiger - 'Install' Remote Command Execution (Metasploit)
CVE-2014-2268remotephp10 abr 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RIESGO
abrir
GitHub PoC8
Heartbleed variants
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
CVE-2014-0160 mass test against subdomains
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
ice-security88/CVE-2014-0160
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC1
OpenSSL Heartbleed (CVE-2014-0160) Fix script
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2850remoteunix10 abr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Orbit Open Ad Server 1.1.0 - SQL Injection
CVE-2014-2540webappsphp10 abr 2014
SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra
23RIESGO
abrir
anteriorpágina 1106 / 2701siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.