Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution)
CVE-2014-3704webappsphp03 nov 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-62771webappsphp03 nov 2014
20RIESGO
abrir
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
CVE-2014-7196webappsphp03 nov 2014
20RIESGO
abrir
Exploit-DB
Who's Who Script - Cross-Site Request Forgery (Add Admin)
CVE-2014-8953webappsphp31 oct 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to
23RIESGO
abrir
Exploit-DB
Progress OpenEdge 11.2 - Directory Traversal
CVE-2014-8555webappsjsp31 oct 2014
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attack
23RIESGO
abrir
Exploit-DB
Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 - '.wax' File Buffer Overflow (Denial of Service) (PoC) EIP Overwrite
CVE-2014-9448doswindows29 oct 2014
Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or
23RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7910remotelinux29 oct 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7169CRITICALbajo ataqueremotelinux29 oct 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
Konke Smart Plug K - Authentication Bypass
CVE-2014-7279remotehardware29 oct 2014
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equ
28RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3671remotelinux29 oct 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotelinux29 oct 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7227remotelinux29 oct 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-7196remotelinux29 oct 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-3659remotelinux29 oct 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CVE-2014-62771remotelinux29 oct 2014
20RIESGO
abrir
Exploit-DB
IBM Tivoli Monitoring 6.2.2 kbbacf1 - Local Privilege Escalation
CVE-2013-5467locallinux29 oct 2014
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Mo
23RIESGO
abrir
Exploit-DBVexDay Proof
MAARCH 1.4 - Arbitrary File Upload
CVE-2015-1587webappsphp29 oct 2014
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - TrackPopupMenu Win32k Null Pointer Dereference (MS14-058) (Metasploit)
CVE-2014-4113HIGHbajo ataquelocalwindows28 oct 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DBVexDay Proof
Enalean Tuleap 7.4.99.5 - Blind SQL Injection
CVE-2014-7176webappsphp28 oct 2014
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
CVE-2014-7176webappsphp28 oct 2014
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Enalean Tuleap 7.4.99.5 - Remote Command Execution
CVE-2014-7178webappsphp28 oct 2014
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is
23RIESGO
abrir
Exploit-DB
Tapatalk for vBulletin 4.x - Blind SQL Injection
CVE-2014-2023webappsphp28 oct 2014
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Enalean Tuleap 7.2 - XML External Entity File Disclosure
CVE-2014-7177webappsphp28 oct 2014
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary
23RIESGO
abrir
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8654webappshardware27 oct 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wirele
23RIESGO
abrir
Exploit-DB
Incredible PBX 2.0.6.5.0 - Remote Command Execution
CVE-2014-9001webappsphp27 oct 2014
reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via s
23RIESGO
abrir
Exploit-DB
WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection
CVE-2014-8586webappsphp27 oct 2014
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8655webappshardware27 oct 2014
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RIESGO
abrir
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8653webappshardware27 oct 2014
Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 wit
23RIESGO
abrir
Exploit-DB
Filemaker Pro 13.03 / Advanced 12.04 - Authentication Bypass / Privilege Escalation
CVE-2014-8347localwindows27 oct 2014
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8656webappshardware27 oct 2014
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a d
28RIESGO
abrir
anteriorpágina 211 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.