Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Dolibarr ERP/CRM 3.5.3 - Multiple Vulnerabilities
CVE-2014-3991webappsphp08 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-1805doswindows_x8608 jul 2014
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-2754doswindows_x8608 jul 2014
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RIESGO
abrir
Exploit-DB
Yokogawa CS3000 - 'BKFSim_vhfd.exe' Remote Buffer Overflow (Metasploit)
CVE-2014-3888remotewindows08 jul 2014
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-1795doswindows_x8608 jul 2014
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-1791doswindows_x8608 jul 2014
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-1777doswindows_x8608 jul 2014
Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site,
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-2775doswindows_x8608 jul 2014
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-2776doswindows_x8608 jul 2014
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-1766doswindows_x8608 jul 2014
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9/10 - CFormElement Use-After-Free / Memory Corruption (PoC) (MS14-035)
CVE-2014-1797doswindows_x8608 jul 2014
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (me
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin MailPoet Newsletters 2.6.8 - 'wysija-newsletters' Arbitrary File Upload (Metasploit)
CVE-2014-4725remotephp07 jul 2014
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RIESGO
abrir
Exploit-DBVexDay Proof
Gitlist - Remote Command Execution (Metasploit)
CVE-2014-4511remotemultiple07 jul 2014
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir
Exploit-DBVexDay Proof
xClassified - 'ads.php' SQL Injection
CVE-2014-4741webappsphp07 jul 2014
SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Exploit-DBVexDay Proof
Gitlist - Remote Command Execution (Metasploit)
CVE-2013-7392remotemultiple07 jul 2014
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Event Processing FileUploadServlet - Arbitrary File Upload (Metasploit)
CVE-2014-2424remotewindows07 jul 2014
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RIESGO
abrir
Exploit-DBVexDay Proof
AtomCMS - SQL Injection / Arbitrary File Upload
CVE-2014-4852webappsphp07 jul 2014
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Frog CMS 0.9.5 - Arbitrary File Upload
CVE-2014-4912webappsphp06 jul 2014
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
23RIESGO
abrir
Exploit-DBVexDay Proof
Ubisoft Uplay 4.6 - Insecure File Permissions Privilege Escalation
CVE-2014-5453localwindows03 jul 2014
Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory
23RIESGO
abrir
Exploit-DB
Baidu Spark Browser 26.5.9999.3511 - Remote Stack Overflow (Denial of Service)
CVE-2014-5349doswindows02 jul 2014
Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (
23RIESGO
abrir
Exploit-DB
Kerio Control 8.3.1 - Blind SQL Injection
CVE-2014-3857webappsphp02 jul 2014
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0867webappsjsp01 jul 2014
rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM A
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0866webappsjsp01 jul 2014
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext c
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP + EMET 4.1.x Bypass) (MS12-037)
CVE-2012-1876remotewindows01 jul 2014
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0894webappsjsp01 jul 2014
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-de
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0871webappsjsp01 jul 2014
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote att
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0870webappsjsp01 jul 2014
Multiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 be
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0869webappsjsp01 jul 2014
The decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algori
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0868webappsjsp01 jul 2014
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-
23RIESGO
abrir
Exploit-DB
IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities
CVE-2014-0864webappsjsp01 jul 2014
Multiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5
23RIESGO
abrir
anteriorpágina 224 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.