Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.805 exploits
Exploit-DB
CS-Cart 4.2.4 - Cross-Site Request Forgery
CVE-2015-2701webappsphp11 mar 2015
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RIESGO
abrir
Exploit-DB
Foxit Products GIF Conversion - 'LZWMinimumCodeSize' Memory Corruption
CVE-2015-2790doswindows11 mar 2015
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2015-1427CRITICALbajo ataqueremotelinux11 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Exploit-DB
Foxit Products GIF Conversion - 'DataSubBlock' Memory Corruption
CVE-2015-2790doswindows11 mar 2015
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
CVE-2015-0081doswindows11 mar 2015
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2680webappsphp10 mar 2015
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2679webappsphp10 mar 2015
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2678webappsphp10 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RIESGO
abrir
Exploit-DB
CodoForum 2.5.1 - Arbitrary File Download
CVE-2014-9261webappsphp10 mar 2015
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RIESGO
abrir
Metasploit600
Microsoft Windows Shell LNK Code Execution
CVE-2015-009610 mar 2015
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir
Metasploit600
Microsoft Windows Shell LNK Code Execution
CVE-2015-009610 mar 2015
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir
Metasploit600
WordPress WPshop eCommerce Arbitrary File Upload Vulnerability
CVE-2015-10135CRITICAL09 mar 2015
WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
43RIESGO
abrir
Exploit-DBVexDay Proof
Rowhammer - NaCl Sandbox Escape
CVE-2015-3693locallinux_x86-6409 mar 2015
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates fo
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (x86-64) - Rowhammer Privilege Escalation
CVE-2015-0565locallinux_x86-6409 mar 2015
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir
Exploit-DBVexDay Proof
Rowhammer - NaCl Sandbox Escape
CVE-2015-0565locallinux_x86-6409 mar 2015
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir
GitHub PoC85
:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:
CVE-2014-0160HIGHbajo ataque08 mar 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque08 mar 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Elastix 2.x - Blind SQL Injection
CVE-2015-1875webappsphp07 mar 2015
SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attacker
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector 8.10 - Remote Command Execution (Metasploit)
CVE-2014-2623remotewindows06 mar 2015
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir
Exploit-DB
PHP Betoffice (Betster) 1.0.4 - Authentication Bypass / SQL Injection
CVE-2015-2237webappsphp06 mar 2015
Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary
23RIESGO
abrir
Exploit-DB
ProjectSend r561 - SQL Injection
CVE-2015-2564webappsphp06 mar 2015
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.17.5 - IRET Instruction #SS Fault Handling Crash (PoC)
CVE-2014-9322doslinux_x86-6404 mar 2015
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8684remotephp04 mar 2015
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir
Exploit-DB
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
CVE-2014-4943doslinux04 mar 2015
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8687remotephp04 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
CVE-2014-7285remotelinux04 mar 2015
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir
Exploit-DB
SolarWinds Orion Service - SQL Injection
CVE-2014-9566webappswindows04 mar 2015
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir
Exploit-DB
Linux Kernel 3.16.3 - Associative Array Garbage Collection Crash (PoC)
CVE-2014-3631doslinux04 mar 2015
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16
23RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8686remotephp04 mar 2015
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir
Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
CVE-2014-858603 mar 2015
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir
anteriorpágina 1063 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.