Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Metasploit600
ElasticSearch Search Groovy Sandbox Bypass
CVE-2015-1427CRITICALbajo ataque11 feb 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme Holding Pattern - Arbitrary File Upload (Metasploit)
CVE-2015-1172webappslinux11 feb 2015
Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a
50RIESGO
abrir
Exploit-DBVexDay Proof
SixApart MovableType < 5.2.12 - Storable Perl Code Execution (Metasploit)
CVE-2015-1592webappslinux11 feb 2015
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use
60RIESGO
abrir
Exploit-DB
SoftSphere DefenseWall FW/IPS 3.24 - Local Privilege Escalation
CVE-2015-1515localwindows11 feb 2015
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memo
23RIESGO
abrir
Exploit-DB
WordPress Plugin Survey and Poll 1.1 - Blind SQL Injection
CVE-2015-2090webappsphp11 feb 2015
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo
23RIESGO
abrir
Exploit-DB
IBM Endpoint Manager - Persistent Cross-Site Scripting
CVE-2014-6137webappscgi11 feb 2015
Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP EasyCart - Unrestricted Arbitrary File Upload (Metasploit)
CVE-2014-9308webappsphp10 feb 2015
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RIESGO
abrir
Exploit-DB
Fork CMS 3.8.5 - SQL Injection
CVE-2015-1467webappsphp09 feb 2015
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to exec
23RIESGO
abrir
Exploit-DB
u5CMS 3.9.3 - 'deletefile.php' Arbitrary File Deletion
CVE-2015-1577webappsphp09 feb 2015
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities
CVE-2014-7863webappsmultiple09 feb 2015
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities
CVE-2014-7864webappsmultiple09 feb 2015
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan
28RIESGO
abrir
Exploit-DB
u5CMS 3.9.3 - Multiple Persistent Cross-Site Scripting / Reflected Cross-Site Scripting Vulnerabilities
CVE-2015-1575webappsphp09 feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Metasploit300
WordPress WPLMS Theme Privilege Escalation
CVE-2015-10139HIGH09 feb 2015
WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation
36RIESGO
abrir
Exploit-DB
RedaxScript CMS 2.2.0 - SQL Injection
CVE-2015-1518webappsphp09 feb 2015
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RIESGO
abrir
Exploit-DB
u5CMS 3.9.3 - Multiple SQL Injections
CVE-2015-1576webappsphp09 feb 2015
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
CVE-2015-1578remotewindows08 feb 2015
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir
Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
CVE-2015-1577remotewindows08 feb 2015
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RIESGO
abrir
Metasploit600
Ektron 8.5, 8.7, 9.0 XSLT Transform Remote Code Execution
CVE-2015-092305 feb 2015
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before
23RIESGO
abrir
Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
CVE-2015-2067webappsphp05 feb 2015
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento
50RIESGO
abrir
Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
CVE-2015-2068webappsphp05 feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server a
43RIESGO
abrir
Exploit-DB
Pragyan CMS 3.0 - SQL Injection
CVE-2015-1471webappsphp04 feb 2015
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DB
BullGuard (Multiple Products) - Arbitrary Write Privilege Escalation
CVE-2014-9642localwindows04 feb 2015
bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca
23RIESGO
abrir
Exploit-DB
K7 Computing (Multiple Products) - Arbitrary Write Privilege Escalation
CVE-2014-9643localwindows04 feb 2015
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users
23RIESGO
abrir
Exploit-DB
AVG Internet Security 2015.0.5315 - Arbitrary Write Privilege Escalation
CVE-2014-9632localwindows04 feb 2015
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec
23RIESGO
abrir
Exploit-DBVexDay Proof
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
CVE-2014-7883webappswindows03 feb 2015
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o
35RIESGO
abrir
Exploit-DB
ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery
CVE-2014-9331webappsmultiple03 feb 2015
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Remote Desktop Services - Web Proxy IE Sandbox Escape (MS15-004) (Metasploit)
CVE-2015-0016HIGHbajo ataquelocalwindows03 feb 2015
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir
Exploit-DB
Sefrengo CMS 1.6.1 - Multiple SQL Injections
CVE-2015-1428webappsphp02 feb 2015
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
GitHub PoC6
A shared library wrapper with additional checks for vulnerable functions gethostbyname2_r gethostbyname_r (GHOST vulnerability)
CVE-2015-023502 feb 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Metasploit500
Adobe Flash Player ByteArray With Workers Use After Free
CVE-2015-0313HIGHbajo ataque02 feb 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir
anteriorpágina 1067 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.