Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-3659remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - Environment Variable Command Injection (Metasploit)
CVE-2014-7910remotecgi25 sep 2014
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-3671remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-7169CRITICALbajo ataqueremotelinux25 sep 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU Bash - 'Shellshock' Environment Variable Command Injection
CVE-2014-3659remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
OSClass 3.4.1 - 'index.php' Local File Inclusion
CVE-2014-6308webappsphp25 sep 2014
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-62771remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Bash - 'Shellshock' Environment Variables Command Injection
CVE-2014-3671remotelinux25 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Webaccess - dvs.ocx GetColor Buffer Overflow (Metasploit)
CVE-2014-2364remotewindows24 sep 2014
Advantech WebAccess Stack-Based Buffer Overflow
68RIESGO
abrir
Exploit-DBVexDay Proof
EMC AlphaStor Device Manager Opcode 0x75 - Command Injection (Metasploit)
CVE-2013-0928remotewindows24 sep 2014
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir
Exploit-DBVexDay Proof
LittleSite 0.1 - 'index.php' Local File Inclusion
CVE-2009-3542webappsphp23 sep 2014
Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to incl
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
CVE-2014-5460webappsphp16 sep 2014
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Modem Routers - Session Hijacking
CVE-2014-6436remotehardware15 sep 2014
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
CVE-2014-6287CRITICALbajo ataqueremotewindows15 sep 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Modem Routers - Information Disclosure
CVE-2014-6437remotehardware15 sep 2014
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configurat
28RIESGO
abrir
Exploit-DBVexDay Proof
Aztech Routers - '/cgi-bin/AZ_Retrain.cgi' Denial of Service
CVE-2014-6435doshardware15 sep 2014
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
28RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Eventlog Analyzer - Arbitrary File Upload (Metasploit)
CVE-2014-6037remotemultiple15 sep 2014
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir
Exploit-DBVexDay Proof
Railo 4.2.1 - Remote File Inclusion (Metasploit)
CVE-2014-5468remotemultiple15 sep 2014
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
50RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central StatusUpdate - Arbitrary File Upload (Metasploit)
CVE-2014-5005remotewindows09 sep 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central StatusUpdate - Arbitrary File Upload (Metasploit)
CVE-2014-5006remotewindows09 sep 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
BulletProof FTP Client 2010 - Buffer Overflow (SEH)
CVE-2014-2973doswindows05 sep 2014
35RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 9.0.1 / Thunderbird 3.1.20 - Information Disclosure
CVE-2014-1564remotemultiple02 sep 2014
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize m
23RIESGO
abrir
Exploit-DBVexDay Proof
Wing FTP Server - (Authenticated) Command Execution (Metasploit)
CVE-2015-4107remotewindows01 sep 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Mulitple WordPress Themes - 'admin-ajax.php?img' Arbitrary File Download
CVE-2014-9734webappsphp01 sep 2014
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att
28RIESGO
abrir
Exploit-DBVexDay Proof
Mulitple WordPress Themes - 'admin-ajax.php?img' Arbitrary File Download
CVE-2015-1579webappsphp01 sep 2014
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin ShortCode 0.2.3 - Local File Inclusion
CVE-2014-5465webappsphp28 ago 2014
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress
28RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit)
CVE-2014-1510remotemultiple28 ago 2014
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and Se
60RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit)
CVE-2014-1511remotemultiple28 ago 2014
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remo
60RIESGO
abrir
Exploit-DBVexDay Proof
glibc - NUL Byte gconv_translit_find Off-by-One
CVE-2014-5119locallinux27 ago 2014
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-depe
28RIESGO
abrir
Exploit-DBVexDay Proof
Granding MA300 - Weak Pin Encryption Brute Force
CVE-2014-5381remotemultiple26 ago 2014
Grand MA 300 allows a brute-force attack on the PIN.
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.