Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
Cart Engine 3.0 - Multiple Vulnerabilities
CVE-2014-8305webappsphp25 sep 2014
Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
OSClass 3.4.1 - 'index.php' Local File Inclusion
CVE-2014-6308webappsphp25 sep 2014
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RIESGO
abrir
Exploit-DB
webEdition 6.3.8.0 (SVN-Revision: 6985) - Directory Traversal
CVE-2014-5258webappsphp24 sep 2014
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated
43RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Webaccess - dvs.ocx GetColor Buffer Overflow (Metasploit)
CVE-2014-2364remotewindows24 sep 2014
Advantech WebAccess Stack-Based Buffer Overflow
68RIESGO
abrir
Exploit-DBVexDay Proof
EMC AlphaStor Device Manager Opcode 0x75 - Command Injection (Metasploit)
CVE-2013-0928remotewindows24 sep 2014
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir
Exploit-DB
Restaurant Script (PizzaInn Project) - Persistent Cross-Site Scripting
CVE-2014-6619webappsphp24 sep 2014
Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 a
23RIESGO
abrir
Exploit-DBVexDay Proof
LittleSite 0.1 - 'index.php' Local File Inclusion
CVE-2009-3542webappsphp23 sep 2014
Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to incl
23RIESGO
abrir
Exploit-DB
M/Monit 3.3.2 - Cross-Site Request Forgery
CVE-2014-6409webappsphp20 sep 2014
Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authe
23RIESGO
abrir
Exploit-DB
M/Monit 3.3.2 - Cross-Site Request Forgery
CVE-2014-6607webappsphp20 sep 2014
M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers
23RIESGO
abrir
Exploit-DB
ClassApps SelectSurvey.net - Multiple SQL Injections
CVE-2014-6030webappsphp20 sep 2014
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RIESGO
abrir
Exploit-DB
Livefyre LiveComments Plugin - Persistent Cross-Site Scripting
CVE-2014-6420webappsphp20 sep 2014
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
CVE-2014-5460webappsphp16 sep 2014
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Modem Routers - Session Hijacking
CVE-2014-6436remotehardware15 sep 2014
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
Railo 4.2.1 - Remote File Inclusion (Metasploit)
CVE-2014-5468remotemultiple15 sep 2014
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
50RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Routers - '/cgi-bin/AZ_Retrain.cgi' Denial of Service
CVE-2014-6435doshardware15 sep 2014
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
28RIESGO
abrir
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
CVE-2014-6287CRITICALbajo ataqueremotewindows15 sep 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Eventlog Analyzer - Arbitrary File Upload (Metasploit)
CVE-2014-6037remotemultiple15 sep 2014
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Modem Routers - Information Disclosure
CVE-2014-6437remotehardware15 sep 2014
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configurat
28RIESGO
abrir
Exploit-DB
CacheGuard-OS 5.7.7 - Cross-Site Request Forgery
CVE-2014-4865webappslinux15 sep 2014
Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central StatusUpdate - Arbitrary File Upload (Metasploit)
CVE-2014-5005remotewindows09 sep 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central StatusUpdate - Arbitrary File Upload (Metasploit)
CVE-2014-5006remotewindows09 sep 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
28RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6050webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6049webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted ins
23RIESGO
abrir
Exploit-DB
Mpay24 PrestaShop Payment Module 1.5 - Multiple Vulnerabilities
CVE-2014-2009webappsphp08 sep 2014
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6046webappsphp08 sep 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack th
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6048webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6047webappsphp08 sep 2014
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by lever
23RIESGO
abrir
Exploit-DB
Mpay24 PrestaShop Payment Module 1.5 - Multiple Vulnerabilities
CVE-2014-2008webappsphp08 sep 2014
SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attacker
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.8.x - Multiple Vulnerabilities
CVE-2014-6045webappsphp08 sep 2014
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to exec
23RIESGO
abrir
Exploit-DB
LoadedCommerce7 - Systemic Query Factory
CVE-2014-5140webappsphp07 sep 2014
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly ha
23RIESGO
abrir
anteriorpágina 217 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.