Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.646 exploits
Exploit-DBVexDay Proof
Bonita BPM 6.5.1 - Multiple Vulnerabilities
CVE-2015-3897webappsjsp10 jun 2015
Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via
43RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2993webappshardware10 jun 2015
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir
Exploit-DB
Alcatel-Lucent OmniSwitch - Cross-Site Request Forgery
CVE-2015-2805webappshardware10 jun 2015
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web int
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-3000webappshardware10 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2994webappshardware10 jun 2015
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2998webappshardware10 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Exploit-DB
FiverrScript - Cross-Site Request Forgery (Add Admin)
CVE-2015-4677webappsphp10 jun 2015
Cross-site request forgery (CSRF) vulnerability in FiverrScript (aka Fiverr Script) 7.2 allows remote attackers to hijac
23RIESGO
abrir
Exploit-DB
Libmimedir - '.VCF' Memory Corruption (PoC)
CVE-2015-3205doslinux10 jun 2015
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file,
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Paypal Currency Converter Basic For WooCommerce - File Read
CVE-2015-5065webappsphp10 jun 2015
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic
28RIESGO
abrir
Exploit-DB
HP WebInspect 10.4 - XML External Entity Injection
CVE-2015-2125webappsxml10 jun 2015
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to by
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2995webappshardware10 jun 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2999webappshardware10 jun 2015
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2996webappshardware10 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
GitHub PoC
reading course
CVE-2014-6271CRITICALbajo ataque10 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Bonita BPM 6.5.1 - Multiple Vulnerabilities
CVE-2015-3898webappsjsp10 jun 2015
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arb
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2997webappshardware10 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account
50RIESGO
abrir
Exploit-DB
ICU library 52 < 54 - Multiple Vulnerabilities
CVE-2014-8147localmultiple10 jun 2015
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in I
28RIESGO
abrir
Exploit-DB
WordPress Plugin Encrypted Contact Form 1.0.4 - Cross-Site Request Forgery
CVE-2015-4010webappsphp10 jun 2015
Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows rem
23RIESGO
abrir
Exploit-DB
ICU library 52 < 54 - Multiple Vulnerabilities
CVE-2014-8146localmultiple10 jun 2015
The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in I
28RIESGO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)
CVE-2015-3306remotelinux10 jun 2015
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Exploit-DB
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
CVE-2015-4119webappsphp10 jun 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac
23RIESGO
abrir
GitHub PoC
redhatkaty/-cve-2010-3904-report
CVE-2010-3904HIGHbajo ataque09 jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir
GitHub PoC
marstornado/cve-2014-0160-Yunfeng-Jiang
CVE-2014-0160HIGHbajo ataque09 jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2010-3904HIGHbajo ataque09 jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHbajo ataque09 jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Milw0rm Clone Script 1.0 - 'related.php?program' Blind SQL Injection
CVE-2015-4137webappsphp09 jun 2015
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
GitHub PoC2
weidongl74/cve-2015-2315-report
CVE-2015-231508 jun 2015
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir
GitHub PoC
system reading course
CVE-2014-6271CRITICALbajo ataque06 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Nmedia WordPress Member Conversation 1.35.0 - 'doupload.php' Arbitrary File Upload
CVE-2012-3577webappsphp05 jun 2015
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress
28RIESGO
abrir
Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
CVE-2015-4465webappsphp04 jun 2015
Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote
23RIESGO
abrir
anteriorpágina 1051 / 2689siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.