Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
GitHub PoC1
This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque17 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
CVE-2015-5079webappsphp17 jun 2015
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RIESGO
abrir
Exploit-DB
TYPO3 Extension Akronymmanager 0.5.0 - SQL Injection
CVE-2015-2803webappsphp16 jun 2015
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RIESGO
abrir
Exploit-DB
Ektron CMS 9.10 SP1 (Build 9.1.0.184.1.114) - Cross-Site Request Forgery
CVE-2015-3624webappsphp16 jun 2015
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails 4.0.x/4.1.x/4.2.x (Web Console v2) - Whitelist Bypass Code Execution (Metasploit)
CVE-2015-3224remotemultiple16 jun 2015
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
CVE-2015-1328locallinux16 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Metasploit400
Overlayfs Privilege Escalation
CVE-2015-132816 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Metasploit600
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution
CVE-2015-322416 jun 2015
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
Metasploit400
Overlayfs Privilege Escalation
CVE-2015-866016 jun 2015
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
CVE-2015-1328locallinux16 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Exploit-DBVexDay Proof
Milw0rm Clone Script 1.0 - '/admin/login.php' Authentication Bypass
CVE-2015-4658webappsphp15 jun 2015
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute
23RIESGO
abrir
Exploit-DB
WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload
CVE-2015-4455webappsphp12 jun 2015
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin
50RIESGO
abrir
Exploit-DB
Opsview 4.6.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2015-4420webappsmultiple12 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SE HTML5 Album Audio Player 1.1.0 - Directory Traversal
CVE-2015-4414webappsphp12 jun 2015
Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)
43RIESGO
abrir
Exploit-DB
ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
CVE-2015-4659webappsphp12 jun 2015
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the auth
23RIESGO
abrir
Exploit-DBVexDay Proof
ZCMS 1.1 - Multiple Vulnerabilities
CVE-2015-7346webappsjsp12 jun 2015
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir
Metasploit300
D-Link Cookie Command Execution
CVE-2025-34125CRITICAL12 jun 2015
D-Link DSP-W110A1 Cookie Command Injection
63RIESGO
abrir
Exploit-DBVexDay Proof
ZCMS 1.1 - Multiple Vulnerabilities
CVE-2015-7347webappsjsp12 jun 2015
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
23RIESGO
abrir
Exploit-DB
OSSEC 2.7 < 2.8.1 - 'diff' Local Privilege Escalation
CVE-2015-3222locallinux11 jun 2015
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
23RIESGO
abrir
Exploit-DB
HP WebInspect 10.4 - XML External Entity Injection
CVE-2015-2125webappsxml10 jun 2015
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to by
23RIESGO
abrir
Exploit-DB
Alcatel-Lucent OmniSwitch - Cross-Site Request Forgery
CVE-2015-2805webappshardware10 jun 2015
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web int
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Paypal Currency Converter Basic For WooCommerce - File Read
CVE-2015-5065webappsphp10 jun 2015
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic
28RIESGO
abrir
Exploit-DBVexDay Proof
Bonita BPM 6.5.1 - Multiple Vulnerabilities
CVE-2015-3897webappsjsp10 jun 2015
Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via
43RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-3000webappshardware10 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar
23RIESGO
abrir
Exploit-DB
FiverrScript - Cross-Site Request Forgery (Add Admin)
CVE-2015-4677webappsphp10 jun 2015
Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijac
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2999webappshardware10 jun 2015
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary
23RIESGO
abrir
Exploit-DB
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
CVE-2015-4118webappsphp10 jun 2015
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated user
23RIESGO
abrir
Exploit-DB
Libmimedir - '.VCF' Memory Corruption (PoC)
CVE-2015-3205doslinux10 jun 2015
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file,
28RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2998webappshardware10 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2995webappshardware10 jun 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
anteriorpágina 1049 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.