Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
CVE-2015-2295webappsphp26 mar 2015
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
RM Downloader 2.7.5.400 - Local Buffer Overflow
CVE-2009-1646localwindows26 mar 2015
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotehardware26 mar 2015
20RIESGO
abrir
Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
CVE-2015-2097remotewindows26 mar 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotehardware26 mar 2015
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALbajo ataqueremotehardware26 mar 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9013webappsphp25 mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir
Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
CVE-2015-0313HIGHbajo ataqueremotewindows25 mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
CVE-2014-9014webappsphp25 mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
CVE-2014-8636remotemultiple24 mar 2015
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
CVE-2011-5165localwindows22 mar 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9013webappsphp22 mar 2015
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir
Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
CVE-2014-9014webappsphp22 mar 2015
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir
Exploit-DB
Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting
CVE-2014-5144webappsphp21 mar 2015
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RIESGO
abrir
Exploit-DB
Joomla! Component ECommerce-WD 1.2.5 - SQL Injection
CVE-2015-2562webappsphp19 mar 2015
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir
Exploit-DBVexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
CVE-2014-7236remotephp19 mar 2015
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DB
Citrix Command Center - Credential Disclosure
CVE-2015-2682webappsxml19 mar 2015
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RIESGO
abrir
Exploit-DB
EMC M&R (Watch4net) - Credential Disclosure
CVE-2015-0514webappsjava19 mar 2015
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RIESGO
abrir
anteriorpágina 198 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.