Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
Exploit-DB
HP WebInspect 10.4 - XML External Entity Injection
CVE-2015-2125webappsxml10 jun 2015
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to by
23RIESGO
abrir
Exploit-DB
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
CVE-2015-4119webappsphp10 jun 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac
23RIESGO
abrir
Exploit-DB
Libmimedir - '.VCF' Memory Corruption (PoC)
CVE-2015-3205doslinux10 jun 2015
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file,
28RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2996webappshardware10 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2995webappshardware10 jun 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Paypal Currency Converter Basic For WooCommerce - File Read
CVE-2015-5065webappsphp10 jun 2015
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic
28RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-3001webappshardware10 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which al
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2999webappshardware10 jun 2015
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary
23RIESGO
abrir
Exploit-DB
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
CVE-2015-4118webappsphp10 jun 2015
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated user
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2998webappshardware10 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-3000webappshardware10 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2993webappshardware10 jun 2015
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHbajo ataque09 jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
redhatkaty/-cve-2010-3904-report
CVE-2010-3904HIGHbajo ataque09 jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir
VulnCheck XDB
local
CVE-2010-3904HIGHbajo ataque09 jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir
GitHub PoC
marstornado/cve-2014-0160-Yunfeng-Jiang
CVE-2014-0160HIGHbajo ataque09 jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Milw0rm Clone Script 1.0 - 'related.php?program' Blind SQL Injection
CVE-2015-4137webappsphp09 jun 2015
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
GitHub PoC2
weidongl74/cve-2015-2315-report
CVE-2015-231508 jun 2015
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir
GitHub PoC
system reading course
CVE-2014-6271CRITICALbajo ataque06 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Nmedia WordPress Member Conversation 1.35.0 - 'doupload.php' Arbitrary File Upload
CVE-2012-3577webappsphp05 jun 2015
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress
28RIESGO
abrir
Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
CVE-2015-4465webappsphp04 jun 2015
Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote
23RIESGO
abrir
Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
CVE-2015-4153webappsphp04 jun 2015
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack
28RIESGO
abrir
Exploit-DBVexDay Proof
SysAid Help Desk Administrator Portal < 14.4 - Arbitrary File Upload (Metasploit)
CVE-2015-2994webappsmultiple03 jun 2015
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir
Metasploit300
SysAid Help Desk Database Credentials Disclosure
CVE-2015-299603 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Metasploit300
SysAid Help Desk Arbitrary File Download
CVE-2015-299603 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Metasploit300
SysAid Help Desk Database Credentials Disclosure
CVE-2015-299803 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Metasploit600
SysAid Help Desk 'rdslogs' Arbitrary File Upload
CVE-2015-299503 jun 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Metasploit600
SysAid Help Desk Administrator Portal Arbitrary File Upload
CVE-2015-299403 jun 2015
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir
Metasploit300
SysAid Help Desk Arbitrary File Download
CVE-2015-299703 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account
50RIESGO
abrir
Metasploit300
SysAid Help Desk Administrator Account Creation
CVE-2015-299303 jun 2015
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir
anteriorpágina 1053 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.