Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.056exploits catalogados
37.663CVEs con explotación pública
24.695probados en laboratorio
81.059 exploits
GitHub PoC
obayesshelton/CVE-2014-0160-Scanner
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
openssl Heart Bleed Exploit: CVE-2014-0160 Mass Security Auditor
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0346remotemultiple08 abr 2014
20RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0160HIGHbajo ataqueremotemultiple08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC40
OpenSSL TLS heartbeat read overrun (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC571
Multi-threaded tool for scanning many hosts for CVE-2014-0160.
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC452
OpenSSL CVE-2014-0160 Heartbleed vulnerability test
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC7
bleed is a tool to test servers for the 'Heartbleed' vulnerability (CVE-2014-0160).
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC2
Mass, multithreaded testing for servers against Heartbleed (CVE-2014-0160).
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC331
Heartbleed (CVE-2014-0160) client exploit
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC19
Patch openssl #heartbleed with ansible
CVE-2014-0160HIGHbajo ataque08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Metasploit600
Sophos Web Protection Appliance Interface Authenticated Arbitrary Command Execution
CVE-2014-285008 abr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RIESGO
abrir
Metasploit600
Sophos Web Protection Appliance Interface Authenticated Arbitrary Command Execution
CVE-2014-284908 abr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RIESGO
abrir
Metasploit300
Advantech WebAccess DBVisitor.dll ChartThemeConfig SQL Injection
CVE-2014-076308 abr 2014
Advantech WebAccess SQL Injection
41RIESGO
abrir
Exploit-DB
Apple Mac OSX 10.9 - Hard Link Memory Corruption
CVE-2013-6799dososx08 abr 2014
Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link
23RIESGO
abrir
GitHub PoC2379
A checker (site and tool) for CVE-2014-0160
CVE-2014-0160HIGHbajo ataque07 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
JIRA Issues Collector - Directory Traversal (Metasploit)
CVE-2014-2314remotewindows07 abr 2014
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque07 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Metasploit300
OpenSSL Heartbeat (Heartbleed) Client Memory Exposure
CVE-2014-0160HIGHbajo ataque07 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Metasploit300
OpenSSL Heartbeat (Heartbleed) Information Leak
CVE-2014-0160HIGHbajo ataque07 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
PHPFox - Access Control Security Bypass
CVE-2013-7196webappsphp05 abr 2014
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restric
23RIESGO
abrir
Exploit-DB
A10 Networks ACOS 2.7.0-P2 (Build 53) - Buffer Overflow (PoC)
CVE-2014-3976doshardware04 abr 2014
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allow
28RIESGO
abrir
Exploit-DB
WordPress Plugin XCloner 3.1.0 - Cross-Site Request Forgery
CVE-2014-2340webappsphp04 abr 2014
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers
23RIESGO
abrir
Metasploit600
Belkin Wemo UPnP Remote Code Execution
CVE-2019-1278004 abr 2014
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetS
40RIESGO
abrir
anteriorpágina 1108 / 2702siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.