Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DB
BisonWare BisonFTP Server 3.5 - Directory Traversal
CVE-2015-7602remotewindows28 sep 2015
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (d
50RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7904webappsjsp28 sep 2015
Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 al
23RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-6493webappsjsp28 sep 2015
Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu
23RIESGO
abrir
Exploit-DB
BMC Track-It! 11.4 - Multiple Vulnerabilities
CVE-2016-6598webappswindows28 sep 2015
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on
28RIESGO
abrir
Metasploit300
PCMan FTP Server 2.0.7 Directory Traversal Information Disclosure
CVE-2015-760128 sep 2015
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..//
50RIESGO
abrir
Metasploit300
BisonWare BisonFTP Server 3.5 Directory Traversal Information Disclosure
CVE-2015-760228 sep 2015
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (d
50RIESGO
abrir
Metasploit600
Vtiger CRM - Authenticated Logo Upload RCE
CVE-2016-171328 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir
Exploit-DB
Adobe Flash - 'uint' Capacity Field
CVE-2015-5568doswindows28 sep 2015
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Ad
28RIESGO
abrir
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2015-6000webappsphp28 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RIESGO
abrir
Metasploit600
Vtiger CRM - Authenticated Logo Upload RCE
CVE-2015-600028 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-6494webappsjsp28 sep 2015
Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430
23RIESGO
abrir
Exploit-DBVexDay Proof
Watchguard XCS - Remote Command Execution (Metasploit)
CVE-2015-5452remotebsd28 sep 2015
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7900webappsjsp28 sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive
23RIESGO
abrir
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2016-1713webappsphp28 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7901webappsjsp28 sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7903webappsjsp28 sep 2015
SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote
23RIESGO
abrir
Exploit-DB
Kaseya Virtual System Administrator (VSA) 7.0 < 9.1 - (Authenticated) Arbitrary File Upload
CVE-2015-6589webappsasp28 sep 2015
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RIESGO
abrir
GitHub PoC11
CVE-2015-3073 PoC
CVE-2015-307327 sep 2015
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir
Exploit-DB
FortiManager 5.2.2 - Persistent Cross-Site Scripting
CVE-2015-8038webappscgi25 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor
23RIESGO
abrir
Exploit-DB
X2Engine 4.2 - Cross-Site Request Forgery
CVE-2015-5075webappsphp25 sep 2015
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RIESGO
abrir
Exploit-DB
X2Engine 4.2 - Arbitrary File Upload
CVE-2015-5074webappsphp25 sep 2015
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php
23RIESGO
abrir
Exploit-DB
FortiManager 5.2.2 - Persistent Cross-Site Scripting
CVE-2015-8037webappscgi25 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque24 sep 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC11
Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)
CVE-2014-0160HIGHbajo ataque24 sep 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
SMF (Simple Machine Forum) 2.0.10 - Remote Memory Exfiltration
CVE-2015-4148webappsphp24 sep 2015
The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtGdiBitBlt' Buffer Overflow (MS15-097)
CVE-2015-2512doswindows_x8624 sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-6008webappsphp23 sep 2015
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands
23RIESGO
abrir
Exploit-DB
Cisco AnyConnect 3.1.08009 - Local Privilege Escalation (via DMG Install Script)
CVE-2015-6306localosx23 sep 2015
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions,
23RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-7382webappsphp23 sep 2015
SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers
23RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-7381webappsphp23 sep 2015
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6
23RIESGO
abrir
anteriorpágina 1035 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.