Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
GitHub PoC94
Gain privileges:system -> root,as a part of https://github.com/retme7/CVE-2014-7911_poc
CVE-2014-432226 ene 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
Exploit-DBVexDay Proof
Android WiFi-Direct - Denial of Service
CVE-2014-0997dosandroid26 ene 2015
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir
Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
CVE-2015-1478webappsmultiple26 ene 2015
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attac
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1373webappsphp26 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inje
23RIESGO
abrir
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-9224webappsmultiple26 ene 2015
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management serve
23RIESGO
abrir
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-7289webappsmultiple26 ene 2015
SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1371webappsphp26 ene 2015
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code b
23RIESGO
abrir
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-9225webappsmultiple26 ene 2015
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symante
23RIESGO
abrir
Exploit-DB
VideoLAN VLC Media Player 2.1.5 - DEP Access Violation
CVE-2014-9597localwindows26 ene 2015
The picture_pool_Delete function in misc/picture_pool.c in VideoLAN VLC media player 2.1.5 allows remote attackers to ex
23RIESGO
abrir
Exploit-DB
ManageEngine ServiceDesk Plus 9.0 < Build 9031 - User Privileges Management
CVE-2015-1480webappsjsp26 ene 2015
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive tic
23RIESGO
abrir
Exploit-DB
VideoLAN VLC Media Player 2.1.5 - Write Access Violation
CVE-2014-9598localwindows26 ene 2015
The picture_Release function in misc/picture.c in VideoLAN VLC media player 2.1.5 allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1374webappsphp26 ene 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers
23RIESGO
abrir
Exploit-DB
Comodo Backup 4.4.0.0 - Null Pointer Dereference Privilege Escalation
CVE-2014-9633localwindows26 ene 2015
The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device ha
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1372webappsphp26 ene 2015
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p
23RIESGO
abrir
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'license.php' Remote Command Execution (Metasploit)
CVE-2012-0261webappsmultiple25 ene 2015
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RIESGO
abrir
Exploit-DB
NPDS CMS REvolution-13 - SQL Injection
CVE-2015-1400webappsphp24 ene 2015
SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DB
Exif Pilot 4.7.2 - Buffer Overflow (SEH)
CVE-2015-1362doswindows22 ene 2015
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RIESGO
abrir
Exploit-DB
ManageEngine ServiceDesk Plus 9.0 - SQL Injection
CVE-2015-1479webappsjsp22 ene 2015
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 buil
23RIESGO
abrir
Exploit-DB
ecommerceMajor - SQL Injection / Authentication Bypass
CVE-2015-1476webappsphp22 ene 2015
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Exploit-DB
Zhone GPON 2520 R4.0.2.566b - Crash (PoC)
CVE-2015-2055doshardware21 ene 2015
Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the
23RIESGO
abrir
Exploit-DB
ArticleFR CMS 3.0.5 - SQL Injection
CVE-2015-1364webappsphp21 ene 2015
SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.
23RIESGO
abrir
Metasploit600
IPass Control Pipe Remote Command Execution
CVE-2015-092521 ene 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir
Metasploit600
WordPress Platform Theme File Upload Vulnerability
CVE-2015-10143CRITICAL21 ene 2015
Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update
43RIESGO
abrir
Metasploit300
Java Secure Socket Extension (JSSE) SKIP-TLS MITM Proxy
CVE-2014-659320 ene 2015
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.
50RIESGO
abrir
GitHub PoC
day6reak/CVE-2014-1773
CVE-2014-177320 ene 2015
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2014-5301remotejava20 ene 2015
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
CVE-2015-1365webappsphp20 ene 2015
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RIESGO
abrir
Exploit-DB
Malwarebytes Anti-Exploit 1.03.1.1220/1.04.1.1012 - Out-of-Bounds Read Denial of Service
CVE-2014-100039doswindows20 ene 2015
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a c
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX networkd - 'effective_audit_token' XPC Type Confusion Sandbox Escape
CVE-2014-4492localosx20 ene 2015
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RIESGO
abrir
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
CVE-2015-1376webappsphp20 ene 2015
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RIESGO
abrir
anteriorpágina 1069 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.