Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
PHPMyRecipes 1.2.2 - 'dosearch.php?words_exact' SQL Injection
CVE-2014-9347webappsphp25 nov 2014
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Exploit-DB
TP-Link TL-WR740N - Denial of Service
CVE-2014-9350doshardware24 nov 2014
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RIESGO
abrir
Exploit-DB
Microsoft Windows 8.1/ Server 2012 - 'Win32k.sys' Local Privilege Escalation (MS14-058)
CVE-2014-4113HIGHbajo ataquelocalwindows24 nov 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DB
RobotStats 1.0 - HTML Injection
CVE-2014-9349dosaix24 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RIESGO
abrir
Exploit-DB
WordPress Plugin wpDataTables 1.5.3 - SQL Injection
CVE-2014-9175webappsphp24 nov 2014
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote
23RIESGO
abrir
Exploit-DB
tcpdump 4.6.2 - Geonet Decoder Denial of Service
CVE-2014-8768dosmultiple24 nov 2014
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow rem
28RIESGO
abrir
Exploit-DB
RobotStats 1.0 - 'robot' SQL Injection
CVE-2014-9348webappsphp24 nov 2014
SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
Advantech EKI-6340 - Command Injection
CVE-2014-8387webappscgi24 nov 2014
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar
35RIESGO
abrir
Exploit-DB
WordPress Plugin DukaPress 2.5.2 - Directory Traversal
CVE-2014-8799webappsphp24 nov 2014
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir
Exploit-DB
WordPress Plugin Download Manager 2.7.2 - Privilege Escalation
CVE-2014-9260webappsphp24 nov 2014
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users
28RIESGO
abrir
Exploit-DBVexDay Proof
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)
CVE-2014-4880remotelinux24 nov 2014
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
50RIESGO
abrir
Exploit-DB
WordPress Plugin CM Download Manager 2.0.0 - Code Injection
CVE-2014-8877webappsphp22 nov 2014
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug
28RIESGO
abrir
Exploit-DB
FluxBB < 1.5.6 - SQL Injection
CVE-2014-10029webappsmultiple21 nov 2014
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SP Client Document Manager 2.4.1 - SQL Injection
CVE-2014-9178webappsphp21 nov 2014
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
CVE-2014-6332HIGHbajo ataqueremotewindows20 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
Snowfox CMS 1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2014-9344webappsphp19 nov 2014
Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authe
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Paid Memberships Pro 1.7.14.2 - Directory Traversal
CVE-2014-8801webappsphp19 nov 2014
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress
28RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (2)
CVE-2014-7146remotephp18 nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
CVE-2014-7146webappsmultiple18 nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
CVE-2014-8598webappsmultiple18 nov 2014
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RIESGO
abrir
Exploit-DB
PHPFox - Persistent Cross-Site Scripting
CVE-2014-8469webappsphp17 nov 2014
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attacker
23RIESGO
abrir
Exploit-DB
Zoph 0.9.1 - Multiple Vulnerabilities
CVE-2014-9236webappsphp17 nov 2014
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier al
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108L - Authentication Bypass (2)
CVE-2014-8493webappshardware17 nov 2014
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108L - Authentication Bypass (1)
CVE-2014-8493webappshardware17 nov 2014
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted reque
23RIESGO
abrir
Exploit-DB
WebsiteBaker 2.8.3 - Multiple Vulnerabilities
CVE-2014-9242webappsphp17 nov 2014
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DB
Maarch LetterBox 2.8 - (Authentication Bypass) Insecure Cookies
CVE-2014-8995webappsphp17 nov 2014
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the Us
23RIESGO
abrir
Exploit-DB
.NET Remoting Services - Remote Command Execution
CVE-2014-1806remotewindows17 nov 2014
The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not pr
35RIESGO
abrir
Exploit-DB
WebsiteBaker 2.8.3 - Multiple Vulnerabilities
CVE-2014-9243webappsphp17 nov 2014
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DB
Proticaret E-Commerce Script 3.0 - SQL Injection (2)
CVE-2014-9237webappsxml17 nov 2014
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 5.1 Bypass) (MS12-037)
CVE-2012-1876remotewindows17 nov 2014
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir
anteriorpágina 208 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.