Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Metasploit300
Moxa Device Credential Retrieval
CVE-2016-9361CRITICAL28 jul 2015
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RIESGO
abrir
Exploit-DBVexDay Proof
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation
CVE-2015-5602locallinux28 jul 2015
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4669webappsphp27 jul 2015
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy
23RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4666webappsphp27 jul 2015
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attack
43RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4667webappsphp27 jul 2015
Multiple hardcoded credentials in Xsuite 2.x.
28RIESGO
abrir
Exploit-DB
WordPress Plugin Count Per Day 3.4 - SQL Injection
CVE-2015-5533webappsphp27 jul 2015
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4665webappsphp27 jul 2015
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3246MEDIUMbajo ataquedoslinux27 jul 2015
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RIESGO
abrir
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3245doslinux27 jul 2015
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4668webappsphp27 jul 2015
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4664webappsphp27 jul 2015
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t
28RIESGO
abrir
Exploit-DB
Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery
CVE-2015-2878webappsmultiple24 jul 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac
23RIESGO
abrir
Metasploit500
Libuser roothelper Privilege Escalation
CVE-2015-324524 jul 2015
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Metasploit500
Libuser roothelper Privilege Escalation
CVE-2015-3246MEDIUMbajo ataque24 jul 2015
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RIESGO
abrir
Metasploit500
Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation
CVE-2015-376021 jul 2015
dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to g
18RIESGO
abrir
Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
CVE-2015-4074webappsphp21 jul 2015
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read ar
50RIESGO
abrir
Exploit-DB
Internet Download Manager - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows21 jul 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
XPCOM - Race Condition
CVE-2005-2414webappsphp21 jul 2015
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remo
23RIESGO
abrir
Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
CVE-2015-4075webappsphp21 jul 2015
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted
23RIESGO
abrir
Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
CVE-2015-4073webappsphp21 jul 2015
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe
23RIESGO
abrir
Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
CVE-2015-4071webappsphp21 jul 2015
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users
23RIESGO
abrir
Exploit-DBVexDay Proof
SysAid Help Desk 'rdslogs' - Arbitrary File Upload (Metasploit)
CVE-2015-2995remotejava21 jul 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
CVE-2015-4072webappsphp21 jul 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote att
23RIESGO
abrir
Exploit-DB
Microsoft Word - Local Machine Zone Code Execution (MS15-022)
CVE-2015-0097localwindows20 jul 2015
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 all
35RIESGO
abrir
Exploit-DB
TcpDump - rpki_rtr_pdu_print Out-of-Bounds Denial of Service
CVE-2015-2153doslinux20 jul 2015
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RIESGO
abrir
Exploit-DB
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1)
CVE-2015-2863webappswindows15 jul 2015
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 b
43RIESGO
abrir
Exploit-DB
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1)
CVE-2015-2862webappswindows15 jul 2015
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18,
23RIESGO
abrir
Exploit-DB
SquirrelMail < 1.4.5-RC1 - Arbitrary Variable Overwrite
CVE-2005-2095webappsphp14 jul 2015
options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which
23RIESGO
abrir
Exploit-DB
sysPass 1.0.9 - SQL Injection
CVE-2015-6516webappsphp14 jul 2015
SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitra
23RIESGO
abrir
Exploit-DB
Pimcore CMS Build 3450 - Directory Traversal
CVE-2015-4425webappsxml14 jul 2015
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permi
23RIESGO
abrir
anteriorpágina 1045 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.