Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
CVE-2015-4553webappsphp29 jun 2015
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RIESGO
abrir
Metasploit600
Watchguard XCS Remote Command Execution
CVE-2015-545329 jun 2015
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RIESGO
abrir
Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
CVE-2005-2112webappsphp29 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir
Metasploit600
Endian Firewall Proxy Password Change Command Injection
CVE-2015-508228 jun 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Metasploit400
Pallete Projects Werkzeug Debugger Remote Code Execution
CVE-2024-34069HIGH28 jun 2015
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
36RIESGO
abrir
Exploit-DBVexDay Proof
Havij - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows27 jun 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
CVE-2015-2169webappswindows26 jun 2015
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RIESGO
abrir
GitHub PoC6
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).
CVE-2014-6271CRITICALbajo ataque26 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque26 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
CVE-2015-4631webappsphp26 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Multiple SQL Injections
CVE-2015-4633webappsphp26 jun 2015
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
CVE-2015-4630webappsphp26 jun 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Directory Traversal
CVE-2015-4632webappsphp26 jun 2015
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RIESGO
abrir
Exploit-DB
Thycotic Secret Server 8.8.000004 - Persistent Cross-Site Scripting
CVE-2015-3443webappsmultiple26 jun 2015
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.3 - 'register.php' SQL Injection
CVE-2015-3933webappsphp24 jun 2015
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
CVE-2015-1701HIGHbajo ataqueransomwarelocalwindows24 jun 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ShaderJob Buffer Overflow (Metasploit)
CVE-2015-3090remotemultiple24 jun 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
CVE-2015-5066webappsphp24 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
CVE-2015-3221webappsphp24 jun 2015
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, a
28RIESGO
abrir
Exploit-DBVexDay Proof
Vesta Control Panel 0.9.8 - OS Command Injection
CVE-2015-4117webappsphp24 jun 2015
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
28RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3112doswindows23 jun 2015
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RIESGO
abrir
Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVE-2015-3113HIGHbajo ataque23 jun 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir
Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVE-2015-3043HIGHbajo ataque23 jun 2015
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.gif' Parsing Memory Corruption
CVE-2015-3110doswindows23 jun 2015
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex
28RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3111doswindows23 jun 2015
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RIESGO
abrir
Exploit-DBVexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
CVE-2015-1158remotemultiple22 jun 2015
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir
Exploit-DBVexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
CVE-2007-3071webappswindows19 jun 2015
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RIESGO
abrir
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5149webappsmultiple19 jun 2015
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RIESGO
abrir
Exploit-DBVexDay Proof
Lively Cart - SQL Injection
CVE-2015-5148webappsmultiple19 jun 2015
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RIESGO
abrir
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5150webappsmultiple19 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RIESGO
abrir
anteriorpágina 1048 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.