Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Exploit-DB
Cerb 7.0.3 - Cross-Site Request Forgery
CVE-2015-6545webappsphp02 sep 2015
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the a
23RIESGO
abrir
Exploit-DB
SiS Windows VGA Display Manager 6.14.10.3930 - Write-What-Where (PoC)
CVE-2015-5465doswindows01 sep 2015
Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allow
23RIESGO
abrir
Metasploit600
Nibbleblog File Upload Vulnerability
CVE-2015-696701 sep 2015
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir
Exploit-DB
XGI Windows VGA Display Manager 6.14.10.1090 - Arbitrary Write (PoC)
CVE-2015-5466doswindows01 sep 2015
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.10
23RIESGO
abrir
Exploit-DBVexDay Proof
Bedita 3.5.1 - Cross-Site Scripting
CVE-2015-6809webappsphp01 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DB
Cyberoam Firewall CR500iNG-XP 10.6.2 MR-1 - Blind SQL Injection
CVE-2015-6811webappshardware31 ago 2015
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlie
23RIESGO
abrir
Exploit-DBVexDay Proof
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
CVE-2015-7243localwindows31 ago 2015
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir
Metasploit300
Boxoft WAV to MP3 Converter v1.1 Buffer Overflow
CVE-2015-724331 ago 2015
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir
Exploit-DB
Ganglia Web Frontend < 3.5.1 - PHP Code Execution
CVE-2012-3448webappsphp31 ago 2015
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)
CVE-2015-3673localosx31 ago 2015
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RIESGO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.0.7 - 'RENAME' Remote Buffer Overflow
CVE-2013-4730remotewindows29 ago 2015
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Metasploit600
phpFileManager 0.9.8 Remote Code Execution
CVE-2015-595828 ago 2015
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
23RIESGO
abrir
Metasploit600
WordPress Responsive Thumbnail Slider Arbitrary File Upload
CVE-2015-10144HIGH28 ago 2015
Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
36RIESGO
abrir
Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
CVE-2015-6568webappsphp28 ago 2015
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir
Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
CVE-2015-6567webappsphp28 ago 2015
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle GlassFish Server 4.1 - Directory Traversal
CVE-2017-1000028webappsmultiple27 ago 2015
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
Exploit-DBVexDay Proof
QEMU - Programmable Interrupt Timer Controller Heap Overflow
CVE-2015-3214dosmultiple27 ago 2015
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read
23RIESGO
abrir
Exploit-DB
Invision Power Board (IP.Board) 4.x - Persistent Cross-Site Scripting
CVE-2015-6810webappsphp27 ago 2015
Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB,
23RIESGO
abrir
GitHub PoC2
An implementation of the CVE-2015-2153 exploit.
CVE-2015-215327 ago 2015
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RIESGO
abrir
Exploit-DB
Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation
CVE-2013-1763locallinux_x86-6426 ago 2015
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RIESGO
abrir
Exploit-DB
Magento eCommerce - Remote Code Execution
CVE-2015-1397webappsxml26 ago 2015
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - OneTableDocumentStream Invalid Object
CVE-2015-0065doswindows25 ago 2015
Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
35RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection
CVE-2016-6195webappsphp25 ago 2015
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 bef
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - Malformed Document Stack Buffer Overflow
CVE-2015-0064doswindows25 ago 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applica
28RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
CVE-2015-0816remotemultiple24 ago 2015
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RIESGO
abrir
Exploit-DB
Pligg CMS 2.0.2 - Cross-Site Request Forgery (Add Admin)
CVE-2015-6655webappsphp24 ago 2015
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
CVE-2015-0802remotemultiple24 ago 2015
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir
Metasploit300
Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow
CVE-2015-776823 ago 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir
Metasploit600
MVPower DVR Shell Unauthenticated Command Execution
CVE-2016-20016CRITICAL23 ago 2015
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'OGL.dll' DpOutputSpanStretch::OutputSpan Out of Bounds Write (MS15-080)
CVE-2015-2431doswindows21 ago 2015
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lyn
28RIESGO
abrir
anteriorpágina 1040 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.