Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
CVE-2014-0160HIGHbajo ataqueremotemultiple24 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Local Security Bypass
CVE-2014-1322localosx22 abr 2014
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0634remotewindows21 abr 2014
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Regular Expression Heap Overflow (Metasploit)
CVE-2013-0633remotewindows21 abr 2014
Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10
28RIESGO
abrir
Exploit-DBVexDay Proof
SAP Router - Timing Attack Password Disclosure
CVE-2014-0984remotehardware17 abr 2014
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CMarkup Use-After-Free (MS14-012) (Metasploit)
CVE-2014-0322HIGHbajo ataqueremotewindows16 abr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Exploit-DBVexDay Proof
Jzip - Buffer Overflow (PoC) (SEH Unicode)
CVE-2010-5300doswindows16 abr 2014
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash
28RIESGO
abrir
Exploit-DBVexDay Proof
lxml - 'clean_html' Security Bypass
CVE-2014-3146MEDIUMremotelinux15 abr 2014
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct
33RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Reader for Android 11.1.3 - Arbitrary JavaScript Execution
CVE-2014-0514localandroid15 abr 2014
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RIESGO
abrir
Exploit-DBVexDay Proof
Xangati XSR / XNR - 'gui_input_test.pl' Remote Command Execution
CVE-2014-0358webappscgi14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 10 - CMarkup Use-After-Free (MS14-012)
CVE-2014-0322HIGHbajo ataqueremotewindows14 abr 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/MGConfigData' Multiple Directory Traversals
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Xangati - '/servlet/Installer?file' Directory Traversal
CVE-2014-0358webappsjsp14 abr 2014
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
CVE-2014-0346remotemultiple10 abr 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
Vtiger - 'Install' Remote Command Execution (Metasploit)
CVE-2014-2268remotephp10 abr 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2850remoteunix10 abr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
CVE-2014-0160HIGHbajo ataqueremotemultiple10 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
CVE-2014-1761HIGHbajo ataquelocalwindows10 abr 2014
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
CVE-2014-2849remoteunix10 abr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
CVE-2014-0160HIGHbajo ataqueremotemultiple09 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
CVE-2014-0346remotemultiple09 abr 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0160HIGHbajo ataqueremotemultiple08 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
CVE-2014-0346remotemultiple08 abr 2014
20RIESGO
abrir
Exploit-DBVexDay Proof
JIRA Issues Collector - Directory Traversal (Metasploit)
CVE-2014-2314remotewindows07 abr 2014
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RIESGO
abrir
Exploit-DBVexDay Proof
PHPFox - Access Control Security Bypass
CVE-2013-7196webappsphp05 abr 2014
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restric
23RIESGO
abrir
Exploit-DBVexDay Proof
ibstat $PATH - Local Privilege Escalation (Metasploit)
CVE-2013-4011locallinux04 abr 2014
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir
Exploit-DBVexDay Proof
SePortal 2.5 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2008-5191remotephp31 mar 2014
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir
Exploit-DBVexDay Proof
Fitnesse Wiki - Remote Command Execution (Metasploit)
CVE-2014-1216remotewindows28 mar 2014
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAN
23RIESGO
abrir
Exploit-DBVexDay Proof
Katello (RedHat Satellite) - users/update_roles Missing Authorisation (Metasploit)
CVE-2013-2143remotelinux26 mar 2014
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RIESGO
abrir
Exploit-DBVexDay Proof
InterWorx Control Panel 5.0.13 build 574 - 'xhr.php?i' SQL Injection
CVE-2014-2531webappsphp26 mar 2014
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.