Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
CVE-2014-8655webappshardware27 oct 2014
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RIESGO
abrir
Exploit-DB
Mulesoft ESB Runtime 3.5.1 - Privilege Escalation
CVE-2014-9000webappsjsp27 oct 2014
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows
23RIESGO
abrir
Exploit-DB
Filemaker Pro 13.03 / Advanced 12.04 - Authentication Bypass / Privilege Escalation
CVE-2014-8347localwindows27 oct 2014
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
CVE-2014-2647webappsmultiple27 oct 2014
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RIESGO
abrir
Exploit-DBVexDay Proof
Centreon - SQL Injection / Command Injection (Metasploit)
CVE-2014-3828remoteunix27 oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir
Exploit-DB
Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion
CVE-2014-8770webappsphp25 oct 2014
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an
23RIESGO
abrir
Exploit-DB
Dell EqualLogic Storage - Directory Traversal
CVE-2013-3304webappshardware25 oct 2014
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary
23RIESGO
abrir
Exploit-DB
WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload
CVE-2014-8739webappsphp25 oct 2014
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir
Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
CVE-2014-6352HIGHbajo ataqueremotewindows25 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
CVE-2014-4114HIGHbajo ataqueremotewindows25 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DB
Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery)
CVE-2013-7057webappsphp23 oct 2014
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to
23RIESGO
abrir
Exploit-DB
iBackup 10.0.0.32 - Local Privilege Escalation
CVE-2014-5507localwindows22 oct 2014
iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user
23RIESGO
abrir
Exploit-DBVexDay Proof
Numara / BMC Track-It! FileStorageService - Arbitrary File Upload (Metasploit)
CVE-2014-4872remotewindows21 oct 2014
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Akeeba Kickstart - Unserialize Remote Code Execution (Metasploit)
CVE-2014-7228remotephp21 oct 2014
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
CVE-2014-6352HIGHbajo ataquelocalwindows_x8620 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux PolicyKit - Race Condition Privilege Escalation (Metasploit)
CVE-2011-1485locallinux20 oct 2014
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RIESGO
abrir
Exploit-DB
Aireplay-ng 1.2 beta3 - 'tcp_test' Length Stack Overflow
CVE-2014-8322remotelinux20 oct 2014
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RIESGO
abrir
Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
CVE-2014-4114HIGHbajo ataquelocalwindows20 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
CVE-2014-6352HIGHbajo ataquelocalwindows20 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
CVE-2014-4114HIGHbajo ataquelocalwindows_x8620 oct 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
CVE-2014-3704webappsphp17 oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DBVexDay Proof
SAP NetWeaver Enqueue Server - Denial of Service
CVE-2014-0995doswindows17 oct 2014
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
23RIESGO
abrir
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
CVE-2014-3704webappsphp17 oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DBVexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
CVE-2014-3704webappsphp16 oct 2014
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
CVE-2014-4971localwindows_x8615 oct 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3829webappslinux15 oct 2014
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RIESGO
abrir
Exploit-DBVexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
CVE-2014-3828webappslinux15 oct 2014
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir
Exploit-DBVexDay Proof
YourMembers Plugin - Blind SQL Injection
CVE-2014-100003webappsphp14 oct 2014
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RIESGO
abrir
Exploit-DB
Tenda A32 Router - Cross-Site Request Forgery
CVE-2014-7281webappshardware14 oct 2014
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RIESGO
abrir
Exploit-DB
Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
CVE-2014-8577webappsphp14 oct 2014
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
anteriorpágina 212 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.