Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Caldera - '/costview2/printers.php?tr' SQL Injection
CVE-2014-2934webappsphp07 may 2014
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Integer Underflow Remote Code Execution (Metasploit)
CVE-2014-0497HIGHbajo ataqueremotewindows06 may 2014
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NTUserMessageCall Win32k Kernel Pool Overflow 'schlamperei.x86.dll' (MS13-053) (Metasploit)
CVE-2013-1300localwindows_x8606 may 2014
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir
Exploit-DB
F5 BIG-IQ 4.1.0.2013.0 - Privilege Escalation (Metasploit)
CVE-2014-3220remotehardware02 may 2014
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary u
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0113remotemultiple02 may 2014
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict
45RIESGO
abrir
Exploit-DB
F5 BIG-IQ 4.1.0.2013.0 - Privilege Escalation (Metasploit)
CVE-2014-2937remotehardware02 may 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0094remotemultiple02 may 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CVE-2014-0112remotemultiple02 may 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir
Exploit-DB
Fritz!Box - Remote Command Execution
CVE-2014-9727webappshardware01 may 2014
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t
60RIESGO
abrir
Exploit-DB
Beetel 450TC2 Router - Cross-Site Request Forgery (Admin Password)
CVE-2014-3792webappshardware30 abr 2014
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Type Confusion Remote Code Execution (Metasploit)
CVE-2013-5331remotewindows29 abr 2014
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RIESGO
abrir
Exploit-DB
GeoCore MAX DB Ver. 7.3.3 - Blind SQL Injection
CVE-2014-3871webappsphp28 abr 2014
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-8949webappsphp28 abr 2014
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitr
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-8948webappsphp28 abr 2014
Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows re
23RIESGO
abrir
Exploit-DB
GeoCore MAX DB Ver. 7.3.3 - Blind SQL Injection
CVE-2006-3823webappsphp28 abr 2014
SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 1.8.12/1.10.5 - wiretap/mpeg.c Stack Buffer Overflow (Metasploit)
CVE-2014-2299localwindows28 abr 2014
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-3842webappsphp28 abr 2014
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-3848webappsphp28 abr 2014
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o
23RIESGO
abrir
Exploit-DB
WordPress Plugin iMember360 3.8.012 < 3.9.001 - Multiple Vulnerabilities
CVE-2014-3849webappsphp28 abr 2014
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attac
23RIESGO
abrir
Exploit-DB
McAfee ePolicy Orchestrator 4.6.0 < 4.6.5 - 'ePowner' Multiple Vulnerabilities
CVE-2013-0140remotewindows28 abr 2014
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x b
23RIESGO
abrir
Exploit-DB
NTP ntpd monlist Query Reflection - Denial of Service
CVE-2013-5211doslinux28 abr 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Exploit-DB
Symantec Endpoint Protection Manager 12.1.x - Overflow (SEH) (PoC)
CVE-2013-1612doswindows27 abr 2014
Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.
23RIESGO
abrir
Exploit-DB
miSecureMessages 4.0.1 - Session Management / Authentication Bypass
CVE-2014-2347webappsmultiple25 abr 2014
AMTELCO miSecure Information Exposure
41RIESGO
abrir
Exploit-DBVexDay Proof
Kolibri Web Server 2.0 - GET Stack Buffer Overflow
CVE-2014-4158remotewindows25 abr 2014
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0160HIGHbajo ataqueremotemultiple24 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Acunetix 8 build 20120704 - Remote Stack Overflow
CVE-2014-2994remotewindows24 abr 2014
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0346remotemultiple24 abr 2014
20RIESGO
abrir
Exploit-DB
WD Arkeia Virtual Appliance 10.2.9 - Local File Inclusion
CVE-2014-2846webappsphp24 abr 2014
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmw
23RIESGO
abrir
Exploit-DBVexDay Proof
dompdf 0.6.0 - 'dompdf.php?read' Arbitrary File Read
CVE-2014-2383webappsphp24 abr 2014
dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroo
50RIESGO
abrir
Exploit-DB
HP Laser Jet - JavaScript Persistent Cross-Site Scripting via PJL Directory Traversal
CVE-2010-4107webappshardware23 abr 2014
The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printer
28RIESGO
abrir
anteriorpágina 229 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.