Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.805 exploits
Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
CVE-2014-858603 mar 2015
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir
Metasploit600
PHPMoAdmin 1.1.2 Remote Code Execution
CVE-2015-220803 mar 2015
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir
Exploit-DB
PHPMoAdmin - Unauthorized Remote Code Execution
CVE-2015-2208webappsphp03 mar 2015
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
CVE-2014-9463webappsphp02 mar 2015
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
CVE-2014-8687webappshardware01 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir
Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CVE-2014-868601 mar 2015
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir
Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CVE-2014-868701 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir
Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CVE-2014-868401 mar 2015
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir
Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
CVE-2015-1497remotewindows27 feb 2015
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Exploit-DB
SQLite3 3.8.6 - Controlled Memory Corruption (PoC)
CVE-2015-5895doslinux26 feb 2015
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and a
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
CVE-2015-1187CRITICALbajo ataquewebappslinux26 feb 2015
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir
Metasploit300
D-Link/TRENDnet NCC Service Command Injection
CVE-2015-1187CRITICALbajo ataque26 feb 2015
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir
Metasploit300
WordPress WP EasyCart Plugin Privilege Escalation
CVE-2015-267325 feb 2015
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC
23RIESGO
abrir
Metasploit300
WordPress Contus Video Gallery Unauthenticated SQL Injection Scanner
CVE-2015-206524 feb 2015
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir
Metasploit300
Solarwinds Orion AccountManagement.asmx GetAccounts Admin Creation
CVE-2014-956624 feb 2015
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir
Exploit-DBVexDay Proof
HP Client - Automation Command Injection (Metasploit)
CVE-2015-1497remotemultiple24 feb 2015
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2015-2183webappsphp23 feb 2015
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execut
23RIESGO
abrir
Exploit-DB
Beehive Forum 1.4.4 - Persistent Cross-Site Scripting
CVE-2015-2198webappsphp23 feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i
23RIESGO
abrir
Exploit-DB
WordPress Plugin Easy Social Icons 1.2.2 - Cross-Site Request Forgery
CVE-2015-2084webappsphp23 feb 2015
Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote
23RIESGO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2142webappsphp23 feb 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authe
23RIESGO
abrir
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2015-2182webappsphp23 feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Metasploit500
D-Link DCS-931L File Upload
CVE-2015-204923 feb 2015
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir
Exploit-DB
Zabbix 2.0.5 - Cleartext ldap_bind_Password Password Disclosure (Metasploit)
CVE-2013-5572webappsphp23 feb 2015
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console acces
23RIESGO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2145webappsphp23 feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to
23RIESGO
abrir
Exploit-DB
PHP DateTime - Use-After-Free
CVE-2015-0273dosphp23 feb 2015
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x befo
35RIESGO
abrir
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2015-2184webappsphp23 feb 2015
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RIESGO
abrir
Exploit-DB
Clipbucket 2.7 RC3 0.9 - Blind SQL Injection
CVE-2015-2102webappsphp23 feb 2015
SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execut
23RIESGO
abrir
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2010-5322webappsphp23 feb 2015
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2143webappsphp23 feb 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac
23RIESGO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2004-1519webappsphp23 feb 2015
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
anteriorpágina 1064 / 2694siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.