Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.799exploits catalogados
37.490CVEs con explotación pública
24.695probados en laboratorio
80.803 exploits
Exploit-DB
Citrix Command Center - Credential Disclosure
CVE-2015-2682webappsxml19 mar 2015
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RIESGO
abrir
Exploit-DB
EMC M&R (Watch4net) - Directory Traversal
CVE-2015-0516webappsjava19 mar 2015
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authen
23RIESGO
abrir
Exploit-DB
EMC M&R (Watch4net) - Credential Disclosure
CVE-2015-0514webappsjava19 mar 2015
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RIESGO
abrir
Exploit-DB
Joomla! Component ECommerce-WD 1.2.5 - SQL Injection
CVE-2015-2562webappsphp19 mar 2015
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir
Exploit-DBVexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
CVE-2014-7236remotephp19 mar 2015
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
CVE-2014-0980localwindows19 mar 2015
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DB
Websense Appliance Manager - Command Injection
CVE-2015-2746webappsjava18 mar 2015
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON
28RIESGO
abrir
Exploit-DBVexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
CVE-2015-0235remotelinux18 mar 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet Single Sign On - Stack Overflow
CVE-2015-2281doswindows18 mar 2015
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RIESGO
abrir
Exploit-DB
Moodle 2.5.9/2.6.8/2.7.5/2.8.3 - Block Title Handler Cross-Site Scripting
CVE-2015-2269webappsphp17 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
CVE-2015-0318remotewindows17 mar 2015
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2791webappsphp16 mar 2015
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
CVE-2015-2292webappsphp16 mar 2015
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RIESGO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2314webappsphp16 mar 2015
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
CVE-2015-1427CRITICALbajo ataqueremotejava16 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Exploit-DBVexDay Proof
IPass Control Pipe - Remote Command Execution (Metasploit)
CVE-2015-0925remotewindows16 mar 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2315webappsphp16 mar 2015
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir
Exploit-DB
Foxit Reader 7.0.6.1126 - Unquoted Service Path Privilege Escalation
CVE-2015-2789localwindows16 mar 2015
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.
23RIESGO
abrir
Exploit-DB
Intel Network Adapter Diagnostic Driver - IOCTL Handling
CVE-2015-2291HIGHbajo ataqueransomwaredoswindows14 mar 2015
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
Metasploit600
Wordpress Work The Flow Upload Vulnerability
CVE-2015-10138CRITICAL14 mar 2015
Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload
63RIESGO
abrir
Metasploit600
Solarwinds Firewall Security Manager 6.6.5 Client Session Handling Vulnerability
CVE-2015-228413 mar 2015
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privile
60RIESGO
abrir
Exploit-DB
WoltLab Community Gallery - Persistent Cross-Site Scripting
CVE-2015-2275webappsphp13 mar 2015
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RIESGO
abrir
Exploit-DB
ArcSight Logger - Arbitrary File Upload / Code Execution
CVE-2014-7884remotelinux13 mar 2015
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated att
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray UncompressViaZlibVariant Use-After-Free (Metasploit)
CVE-2015-0311HIGHbajo ataqueremotewindows12 mar 2015
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RIESGO
abrir
Metasploit500
Adobe Flash Player NetConnection Type Confusion
CVE-2015-033612 mar 2015
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir
Metasploit600
iPass Mobile Client Service Privilege Escalation
CVE-2015-092512 mar 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir
Exploit-DB
Ubuntu 15.04 (Development) - 'Upstart' Logrotation Privilege Escalation
CVE-2015-2285locallinux12 mar 2015
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu
23RIESGO
abrir
Exploit-DB
Citrix Netscaler NS10.5 - WAF Bypass (Via HTTP Header Pollution)
CVE-2015-2841webappsxml12 mar 2015
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restriction
23RIESGO
abrir
Exploit-DB
CS-Cart 4.2.4 - Cross-Site Request Forgery
CVE-2015-2701webappsphp11 mar 2015
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2015-1427CRITICALbajo ataqueremotelinux11 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
anteriorpágina 1062 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.