Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8673webappsphp13 jul 2015
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in
28RIESGO
abrir
Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
CVE-2015-5591webappsphp13 jul 2015
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - opaqueBackground Use-After-Free (Metasploit)
CVE-2015-5122HIGHbajo ataqueremotewindows13 jul 2015
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8677webappsphp13 jul 2015
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and
23RIESGO
abrir
Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
CVE-2015-5595webappsphp13 jul 2015
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack
23RIESGO
abrir
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8674webappsphp13 jul 2015
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the doc
23RIESGO
abrir
Exploit-DB
ArticleFR 3.0.6 - Multiple Vulnerabilities
CVE-2015-5530webappsphp13 jul 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
Accellion FTA - getStatus verify_oauth_token Command Execution (Metasploit)
CVE-2015-2857remotehardware13 jul 2015
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir
Exploit-DB
ArticleFR 3.0.6 - Multiple Vulnerabilities
CVE-2015-5529webappsphp13 jul 2015
Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to injec
23RIESGO
abrir
Exploit-DB
Arab Portal 3 - SQL Injection
CVE-2015-6519webappsphp13 jul 2015
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail
23RIESGO
abrir
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8675webappsphp13 jul 2015
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all
28RIESGO
abrir
Exploit-DBVexDay Proof
Western Digital Arkeia < 11.0.12 - Remote Code Execution (Metasploit)
CVE-2015-7709remotemultiple13 jul 2015
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8676webappsphp13 jul 2015
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
50RIESGO
abrir
Exploit-DB
FreiChat 9.6 - SQL Injection
CVE-2015-6512webappsphp13 jul 2015
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RIESGO
abrir
Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
CVE-2015-5594webappsphp13 jul 2015
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download
CVE-2015-5471webappsphp13 jul 2015
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo
50RIESGO
abrir
GitHub PoC15
Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed
CVE-2014-0160HIGHbajo ataque12 jul 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC22
Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock
CVE-2014-6271CRITICALbajo ataque11 jul 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit0
ManageEngine EventLog Analyzer Remote Code Execution
CVE-2015-738711 jul 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Metasploit0
MS15-078 Microsoft Windows Font Driver Buffer Overflow
CVE-2015-2426HIGHbajo ataque11 jul 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir
Metasploit0
MS15-078 Microsoft Windows Font Driver Buffer Overflow
CVE-2015-243311 jul 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
43RIESGO
abrir
Metasploit600
X11 Keyboard Command Injection
CVE-1999-052610 jul 2015
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RIESGO
abrir
Metasploit600
Accellion FTA getStatus verify_oauth_token Command Execution
CVE-2015-285710 jul 2015
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir
Metasploit500
Western Digital Arkeia Remote Code Execution
CVE-2015-770910 jul 2015
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir
Metasploit300
Accellion FTA 'statecode' Cookie Arbitrary File Read
CVE-2015-285610 jul 2015
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices
30RIESGO
abrir
Metasploit300
OpenSSL Alternative Chains Certificate Forgery MITM Proxy
CVE-2015-179309 jul 2015
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
CVE-2015-3043HIGHbajo ataqueremotemultiple08 jul 2015
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir
Exploit-DB
Centreon 2.5.4 - Multiple Vulnerabilities
CVE-2015-1561webappsphp08 jul 2015
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centre
23RIESGO
abrir
Exploit-DB
Orchard CMS 1.7.3/1.8.2/1.9.0 - Persistent Cross-Site Scripting
CVE-2015-5520webappsasp08 jul 2015
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
AirLive (Multiple Products) - OS Command Injection
CVE-2015-2279webappshardware08 jul 2015
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RIESGO
abrir
anteriorpágina 1046 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.