Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
81.064 exploits
Exploit-DBVexDay Proof
Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections
CVE-2014-1671webappsphp13 ene 2014
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot
23RIESGO
abrir
Exploit-DB
DomPHP 0.83 - Local Directory Traversal
CVE-2014-10037webappsphp12 ene 2014
Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..
43RIESGO
abrir
Metasploit500
HP AutoPass License Server File Upload
CVE-2013-622110 ene 2014
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoP
60RIESGO
abrir
Exploit-DBVexDay Proof
UAEPD Shopping Script - 'news.php?id' SQL Injection
CVE-2014-1618webappsphp08 ene 2014
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
UAEPD Shopping Script - 'products.php' Multiple SQL Injections
CVE-2014-1618webappsphp08 ene 2014
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_grades.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/backup/backup_ray2.php' Database Backup Direct Request Information Disclosure
CVE-2014-1637webappsphp07 ene 2014
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_school_names.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_terms.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_school_years.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_sgrades.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Forms Viewer - Unicode Buffer Overflow (Metasploit)
CVE-2013-5447localwindows07 ene 2014
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RIESGO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.4.0 SOAP - AddEmailAttachment Arbitrary File Upload (Metasploit)
CVE-2013-3214remotephp07 ene 2014
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_subjects.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_media_codes_1.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_titles.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/add_topic.php' Cross-Site Request Forgery (Topic Creation)
CVE-2014-1915webappsphp07 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_infraction_codes.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_generations.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/health_allergies.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
IcoFX - Local Stack Buffer Overflow (Metasploit)
CVE-2013-4988localwindows07 ene 2014
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/admin_relations.php?id' SQL Injection
CVE-2014-1636webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Command School Student Management System - '/sw/Admin_change_Password.php' Cross-Site Request Forgery (Admin Password Manipulation)
CVE-2014-1915webappsphp07 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow rem
23RIESGO
abrir
Exploit-DB
Cubic CMS - Multiple Vulnerabilities
CVE-2014-1619webappsphp07 ene 2014
Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DB
Seagate BlackArmor NAS sg2000-2000.1331 - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2013-6923webappshardware06 ene 2014
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331
23RIESGO
abrir
Exploit-DB
Seagate BlackArmor NAS sg2000-2000.1331 - Cross-Site Request Forgery
CVE-2013-6922webappshardware06 ene 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg200
23RIESGO
abrir
Exploit-DB
Seagate BlackArmor NAS - Privilege Escalation
CVE-2013-6924webappshardware06 ene 2014
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via s
28RIESGO
abrir
Exploit-DB
Seagate BlackArmor NAS sg2000-2000.1331 - Remote Command Execution
CVE-2013-6924webappshardware06 ene 2014
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via s
28RIESGO
abrir
Exploit-DB
Taboada Macronews 1.0 - SQL Injection
CVE-2014-10032webappsphp04 ene 2014
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbi
23RIESGO
abrir
Metasploit600
GetSimpleCMS PHP File Upload Vulnerability
CVE-2013-10032HIGH04 ene 2014
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
36RIESGO
abrir
anteriorpágina 1118 / 2703siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.