Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Authentication Bypass
CVE-2014-922217 dic 2014
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re
30RIESGO
abrir
Metasploit400
Malwarebytes Anti-Malware and Anti-Exploit Update Remote Code Execution
CVE-2014-493616 dic 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir
Metasploit600
Symantec Web Gateway 5 restore.php Post Authentication Command Injection
CVE-2014-728516 dic 2014
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir
Metasploit600
ManageEngine Multiple Products Authenticated File Upload
CVE-2014-530115 dic 2014
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir
Metasploit600
WordPress WP Symposium 14.11 Shell Upload
CVE-2014-1002111 dic 2014
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir
Metasploit600
Lexmark MarkVision Enterprise Arbitrary File Upload
CVE-2014-874109 dic 2014
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RIESGO
abrir
Metasploit300
BMC TrackIt! Unauthenticated Arbitrary User Password Change
CVE-2014-827009 dic 2014
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose na
23RIESGO
abrir
Metasploit600
ProjectSend Arbitrary File Upload
CVE-2014-956702 dic 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir
Metasploit300
ManageEngine NetFlow Analyzer Arbitrary File Download
CVE-2014-544530 nov 2014
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir
Metasploit600
Tuleap PHP Unserialize Code Execution
CVE-2014-879127 nov 2014
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RIESGO
abrir
Metasploit600
WordPress RevSlider File Upload and Execute Vulnerability
CVE-2014-973526 nov 2014
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RIESGO
abrir
Metasploit300
Adobe Flash Player PCRE Regex Vulnerability
CVE-2015-031825 nov 2014
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir
Metasploit300
Arris VAP2500 tools_command.php Command Execution
CVE-2014-842325 nov 2014
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir
Metasploit300
Arris VAP2500 tools_command.php Command Execution
CVE-2014-842425 nov 2014
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio
50RIESGO
abrir
Metasploit300
WordPress Long Password DoS
CVE-2014-901620 nov 2014
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
Metasploit300
Hikvision DVR RTSP Request Remote Code Execution
CVE-2014-488019 nov 2014
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir
Metasploit500
HP Performance Monitoring xglance Priv Esc
CVE-2014-263019 nov 2014
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RIESGO
abrir
Metasploit300
MS14-068 Microsoft Kerberos Checksum Validation Vulnerability
CVE-2014-6324HIGHbajo ataque18 nov 2014
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RIESGO
abrir
Metasploit300
Cisco DLSw Information Disclosure Scanner
CVE-2014-799217 nov 2014
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensiti
23RIESGO
abrir
Metasploit400
MS14-064 Microsoft Internet Explorer Windows OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataque13 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Metasploit600
MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python
CVE-2014-6352HIGHbajo ataque12 nov 2014
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Metasploit400
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
CVE-2014-844011 nov 2014
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RIESGO
abrir
Metasploit600
WordPress Photo Gallery Unrestricted File Upload
CVE-2014-931211 nov 2014
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RIESGO
abrir
Metasploit200
MS14-070 Windows tcpip!SetAddrOptions NULL Pointer Dereference
CVE-2014-407611 nov 2014
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Metasploit500
MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
CVE-2014-714608 nov 2014
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir
Metasploit300
ManageEngine Password Manager SQLAdvancedALSearchResult.cc Pro SQL Injection
CVE-2014-849908 nov 2014
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Servi
50RIESGO
abrir
Metasploit500
MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
CVE-2014-859808 nov 2014
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RIESGO
abrir
Metasploit300
i-FTP Schedule Buffer Overflow
CVE-2014-125114HIGH06 nov 2014
i-Ftp 2.20 Schedule.xml Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit300
ManageEngine Eventlog Analyzer Managed Hosts Administrator Credential Disclosure
CVE-2014-603905 nov 2014
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio
50RIESGO
abrir
Metasploit300
ManageEngine Eventlog Analyzer Managed Hosts Administrator Credential Disclosure
CVE-2014-603805 nov 2014
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.