Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.646 exploits
Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
CVE-2015-4153webappsphp04 jun 2015
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack
28RIESGO
abrir
Exploit-DBVexDay Proof
SysAid Help Desk Administrator Portal < 14.4 - Arbitrary File Upload (Metasploit)
CVE-2015-2994webappsmultiple03 jun 2015
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir
Metasploit300
SysAid Help Desk Arbitrary File Download
CVE-2015-299703 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account
50RIESGO
abrir
Metasploit300
SysAid Help Desk Administrator Account Creation
CVE-2015-299303 jun 2015
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir
Metasploit300
SysAid Help Desk Arbitrary File Download
CVE-2015-299603 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Metasploit300
SysAid Help Desk Database Credentials Disclosure
CVE-2015-299803 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Metasploit300
SysAid Help Desk Database Credentials Disclosure
CVE-2015-299603 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Metasploit600
SysAid Help Desk Administrator Portal Arbitrary File Upload
CVE-2015-299403 jun 2015
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir
Metasploit600
SysAid Help Desk 'rdslogs' Arbitrary File Upload
CVE-2015-299503 jun 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Devices - HNAP SOAPAction-Header Command Execution (Metasploit)
CVE-2015-2051HIGHbajo ataqueremotehardware01 jun 2015
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RIESGO
abrir
Exploit-DBVexDay Proof
Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit)
CVE-2014-8361CRITICALbajo ataqueremotelinux01 jun 2015
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RIESGO
abrir
Exploit-DB
Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting
CVE-2015-1389webappshardware01 jun 2015
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Airties - login-cgi Buffer Overflow (Metasploit)
CVE-2015-2797remotehardware01 jun 2015
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir
Exploit-DB
Peercast < 0.1211 - Format String
CVE-2005-1806doswindows28 may 2015
Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format
28RIESGO
abrir
Exploit-DB
WordPress Plugin Free Counter 1.1 - Persistent Cross-Site Scripting
CVE-2015-4084webappsphp27 may 2015
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities
CVE-2015-4064webappsphp26 may 2015
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
CVE-2015-4063webappsphp26 may 2015
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPres
38RIESGO
abrir
Exploit-DB
Apache JackRabbit - WebDAV XML External Entity
CVE-2015-1833webappsjava26 may 2015
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RIESGO
abrir
Exploit-DB
WordPress Plugin church_admin 0.800 - Persistent Cross-Site Scripting
CVE-2015-4127webappsphp26 may 2015
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers t
38RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
CVE-2015-4062webappsphp26 may 2015
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo
38RIESGO
abrir
Exploit-DBVexDay Proof
Sendio ESP - Information Disclosure
CVE-2014-8391webappsjsp26 may 2015
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RIESGO
abrir
Exploit-DBVexDay Proof
Sendio ESP - Information Disclosure
CVE-2014-0999webappsjsp26 may 2015
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities
CVE-2015-4065webappsphp26 may 2015
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin GigPress 2.3.8 - SQL Injection
CVE-2015-4066webappsphp26 may 2015
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
CVE-2015-0059localwindows25 may 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
28RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
CVE-2015-0003localwindows25 may 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
CVE-2015-0057localwindows25 may 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
28RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
CVE-2015-0058localwindows25 may 2015
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
CVE-2015-0010localwindows25 may 2015
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in M
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
CVE-2015-0060localwindows25 may 2015
The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Window
23RIESGO
abrir
anteriorpágina 1052 / 2689siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.