Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
Advertise With Pleasure! (AWP) 6.6 - SQL Injection
CVE-2014-9345webappscgi04 dic 2014
SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows r
23RIESGO
abrir
Exploit-DB
WordPress Plugin Cart66 Lite eCommerce 1.5.1.17 - Blind SQL Injection
CVE-2014-9305webappsphp03 dic 2014
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RIESGO
abrir
Exploit-DB
BulletProof FTP Client 2010 - Local Buffer Overflow (SEH)
CVE-2014-2973localwindows03 dic 2014
35RIESGO
abrir
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5445webappsmultiple03 dic 2014
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir
Exploit-DB
WordPress Plugin Google Document Embedder 2.5.16 - 'mysql_real_escpae_string' Bypass SQL Injection
CVE-2014-9173webappsphp03 dic 2014
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta
23RIESGO
abrir
Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
CVE-2014-5446webappsmultiple03 dic 2014
Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2
35RIESGO
abrir
Exploit-DBVexDay Proof
Tincd - (Authenticated) Remote TCP Stack Buffer Overflow (Metasploit)
CVE-2013-1428remotemultiple02 dic 2014
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RIESGO
abrir
Exploit-DB
tnftp (FreeBSD 8/9/10) - 'tnftp' Client Side
CVE-2014-8517remotebsd02 dic 2014
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)
CVE-2014-4404HIGHbajo ataquelocalosx02 dic 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RIESGO
abrir
Exploit-DB
EntryPass N5200 - Credentials Exposure
CVE-2014-8868webappshardware02 dic 2014
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain
23RIESGO
abrir
Exploit-DB
TYPO3 Extension ke DomPDF - Remote Code Execution
CVE-2014-6235webappsphp02 dic 2014
Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DB
EntryPass N5200 - Credentials Exposure
CVE-2014-9303webappshardware02 dic 2014
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator
23RIESGO
abrir
Exploit-DB
ProjectSend r-561 - Arbitrary File Upload
CVE-2014-9567webappsphp02 dic 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir
Exploit-DB
Thomson Reuters Fixed Assets CS 13.1.4 - Local Privilege Escalation
CVE-2014-9141localwindows02 dic 2014
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which all
23RIESGO
abrir
Exploit-DB
WordPress Plugin Nextend Facebook Connect 1.4.59 - Cross-Site Scripting
CVE-2014-8800webappsphp02 dic 2014
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before
23RIESGO
abrir
Exploit-DB
WordPress Core 4.0 - Denial of Service
CVE-2014-9034dosphp01 dic 2014
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all
45RIESGO
abrir
Exploit-DB
WordPress Core < 4.0.1 - Denial of Service
CVE-2014-9034dosphp01 dic 2014
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 all
45RIESGO
abrir
Exploit-DB
Drupal < 7.34 - Denial of Service
CVE-2014-9016dosphp01 dic 2014
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
Exploit-DB
CCH Wolters Kluwer PFX Engagement 7.1 - Local Privilege Escalation
CVE-2014-9113localwindows28 nov 2014
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RIESGO
abrir
Exploit-DB
xEpan 1.0.1 - Cross-Site Request Forgery
CVE-2014-8429webappsphp26 nov 2014
Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows
23RIESGO
abrir
Exploit-DB
Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 - '.wax' Local Buffer Overflow (SEH)
CVE-2014-9448localwindows26 nov 2014
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin DB Backup - Arbitrary File Download
CVE-2014-9119webappsphp26 nov 2014
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at
43RIESGO
abrir
Exploit-DB
Elipse E3 - HTTP Denial of Service
CVE-2014-8652doswindows26 nov 2014
Elipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via
23RIESGO
abrir
Exploit-DB
Android WAPPushManager - SQL Injection
CVE-2014-8507dosandroid26 nov 2014
Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/Wap
23RIESGO
abrir
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8425webappshardware25 nov 2014
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the confi
23RIESGO
abrir
Exploit-DB
Arris VAP2500 - Authentication Bypass
CVE-2014-8423webappshardware25 nov 2014
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir
Exploit-DB
PHPMyRecipes 1.2.2 - 'dosearch.php?words_exact' SQL Injection
CVE-2014-9347webappsphp25 nov 2014
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DB
TRENDnet SecurView Wireless Network Camera TV-IP422WN - 'UltraCamX.ocx' Stack Buffer Overflow (PoC)
CVE-2014-10011doswindows25 nov 2014
Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView ca
28RIESGO
abrir
Exploit-DB
WordPress Plugin Google Document Embedder 2.5.14 - SQL Injection
CVE-2014-9173webappsphp25 nov 2014
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.14.5 (CentOS 7 / RHEL) - 'libfutex' Local Privilege Escalation
CVE-2014-3153HIGHbajo ataquelocallinux25 nov 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
anteriorpágina 207 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.