Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Wordpress XMLRPC DoS
CVE-2014-526606 ago 2014
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, doe
23RIESGO
abrir
Metasploit0
HybridAuth install.php PHP Code Execution
CVE-2014-125116CRITICAL04 ago 2014
HybridAuth 2.0.9 - 2.2.2 Unauthenticated RCE via install.php Configuration Injection
63RIESGO
abrir
Metasploit300
BulletProof FTP Client BPS Buffer Overflow
CVE-2014-297324 jul 2014
35RIESGO
abrir
Metasploit600
Dell SonicWALL Scrutinizer 11.01 methodDetail SQL Injection
CVE-2014-497724 jul 2014
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir
Metasploit200
MQAC.sys Arbitrary Write Privilege Escalation
CVE-2014-497122 jul 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Metasploit200
MS14-062 Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation
CVE-2014-497118 jul 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Metasploit300
Advantech WebAccess dvs.ocx GetColor Buffer Overflow
CVE-2014-236417 jul 2014
Advantech WebAccess Stack-Based Buffer Overflow
68RIESGO
abrir
Metasploit200
VirtualBox Guest Additions VBoxGuest.sys Privilege Escalation
CVE-2014-247715 jul 2014
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RIESGO
abrir
Metasploit300
Flash "Rosetta" JSONP GET/POST Response Disclosure
CVE-2014-467108 jul 2014
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Ad
23RIESGO
abrir
Metasploit600
Wordpress MailPoet Newsletters (wysija-newsletters) Unauthenticated File Upload
CVE-2014-472501 jul 2014
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RIESGO
abrir
Metasploit600
Gitlist Unauthenticated Remote Command Execution
CVE-2014-451130 jun 2014
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir
Metasploit600
VMTurbo Operations Manager vmtadmin.cgi Remote Command Execution
CVE-2014-507325 jun 2014
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands
60RIESGO
abrir
Metasploit600
Wing FTP Server Authenticated Command Execution
CVE-2025-47812CRITICALbajo ataque19 jun 2014
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir
Metasploit600
ManageEngine Desktop Central / Password Manager LinkViewFetchServlet.dat SQL Injection
CVE-2014-399608 jun 2014
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central
50RIESGO
abrir
Metasploit300
OpenSSL DTLS Fragment Buffer Overflow DoS
CVE-2014-019505 jun 2014
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0
40RIESGO
abrir
Metasploit300
OpenSSL Server-Side ChangeCipherSpec Injection Scanner
CVE-2014-022405 jun 2014
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph
60RIESGO
abrir
Metasploit0
Chkrootkit Local Privilege Escalation
CVE-2014-047604 jun 2014
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir
Metasploit300
Ericom AccessNow Server Buffer Overflow
CVE-2014-391302 jun 2014
Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrar
50RIESGO
abrir
Metasploit300
Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow
CVE-2014-388823 may 2014
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RIESGO
abrir
Metasploit300
D-Link info.cgi POST Request Buffer Overflow
CVE-2014-125117CRITICAL22 may 2014
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RIESGO
abrir
Metasploit300
Easy File Management Web Server Stack Buffer Overflow
CVE-2014-379120 may 2014
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Metasploit300
D-Link HNAP Request Remote Buffer Overflow
CVE-2014-393615 may 2014
Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06
60RIESGO
abrir
Metasploit600
Symantec Workspace Streaming ManagementAgentServer.putFile XMLRPC Request Arbitrary File Upload
CVE-2014-164912 may 2014
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functional
50RIESGO
abrir
Metasploit300
Belkin Play N750 login.cgi Buffer Overflow
CVE-2014-163509 may 2014
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RIESGO
abrir
Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
CVE-2014-538309 may 2014
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL
43RIESGO
abrir
Metasploit600
AlienVault OSSIM av-centerd Command Injection
CVE-2014-380405 may 2014
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
60RIESGO
abrir
Metasploit600
Android 'Towelroot' Futex Requeue Kernel Exploit
CVE-2014-3153HIGHbajo ataque03 may 2014
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
Metasploit0
Cogent DataHub Command Injection
CVE-2014-378929 abr 2014
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary
50RIESGO
abrir
Metasploit300
Wireshark CAPWAP Dissector DoS
CVE-2013-407428 abr 2014
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.
50RIESGO
abrir
Metasploit500
Adobe Flash Player Shader Buffer Overflow
CVE-2014-051528 abr 2014
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.