Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8674webappsphp13 jul 2015
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the doc
23RIESGO
abrir
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
CVE-2014-8676webappsphp13 jul 2015
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
50RIESGO
abrir
Exploit-DB
Centreon 2.5.4 - Multiple Vulnerabilities
CVE-2015-1560webappsphp08 jul 2015
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir
Exploit-DBVexDay Proof
AirLive (Multiple Products) - OS Command Injection
CVE-2015-2279webappshardware08 jul 2015
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP E-Commerce Shop Styling 2.5 - Arbitrary File Download
CVE-2015-5468webappsphp08 jul 2015
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
CVE-2015-5119HIGHbajo ataqueremotemultiple08 jul 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
CVE-2015-3043HIGHbajo ataqueremotemultiple08 jul 2015
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir
Exploit-DB
Orchard CMS 1.7.3/1.8.2/1.9.0 - Persistent Cross-Site Scripting
CVE-2015-5520webappsasp08 jul 2015
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RIESGO
abrir
Exploit-DB
Centreon 2.5.4 - Multiple Vulnerabilities
CVE-2015-1561webappsphp08 jul 2015
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centre
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
CVE-2015-3113HIGHbajo ataqueremotemultiple08 jul 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir
Exploit-DBVexDay Proof
AirLink101 SkyIPCam1620W - OS Command Injection
CVE-2015-2280webappshardware08 jul 2015
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709
28RIESGO
abrir
Exploit-DB
WordPress Plugin Easy2Map 1.24 - SQL Injection
CVE-2015-4616webappsphp08 jul 2015
Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allo
28RIESGO
abrir
Exploit-DB
WordPress Plugin Easy2Map 1.24 - SQL Injection
CVE-2015-4614webappsphp08 jul 2015
Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow
23RIESGO
abrir
Exploit-DB
phpLiteAdmin 1.1 - Multiple Vulnerabilities
CVE-2015-6517webappsphp07 jul 2015
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication
23RIESGO
abrir
Exploit-DB
phpLiteAdmin 1.1 - Multiple Vulnerabilities
CVE-2015-6518webappsphp07 jul 2015
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DB
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
CVE-2013-0230doshardware07 jul 2015
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RIESGO
abrir
Exploit-DB
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
CVE-2013-0229doshardware07 jul 2015
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RIESGO
abrir
Exploit-DB
PHPXMLRPC < 1.1 - Remote Code Execution
CVE-2005-1921webappsphp02 jul 2015
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PH
60RIESGO
abrir
Exploit-DB
Fiyo CMS 2.0_1.9.1 - SQL Injection
CVE-2015-3934webappsphp30 jun 2015
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DB
C2Box 4.0.0(r19171) - Cross-Site Request Forgery
CVE-2015-4460webappsasp30 jun 2015
Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box befor
23RIESGO
abrir
Exploit-DB
Novius 5.0.1 - Multiple Vulnerabilities
CVE-2015-5354webappsphp30 jun 2015
Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites
43RIESGO
abrir
Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
CVE-2015-4683webappshardware30 jun 2015
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti
23RIESGO
abrir
Exploit-DB
Watchguard XCS 10.0 - Multiple Vulnerabilities
CVE-2011-2165webappsphp30 jun 2015
The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-
23RIESGO
abrir
Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
CVE-2015-4682webappshardware30 jun 2015
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation
23RIESGO
abrir
Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
CVE-2015-4684webappshardware30 jun 2015
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re
23RIESGO
abrir
Exploit-DB
Novius 5.0.1 - Multiple Vulnerabilities
CVE-2015-5353webappsphp30 jun 2015
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir
Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
CVE-2015-4685webappshardware30 jun 2015
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain p
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Drawing Fill Shader Memory Corruption (Metasploit)
CVE-2015-3105remotemultiple30 jun 2015
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466
60RIESGO
abrir
Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
CVE-2015-4681webappshardware30 jun 2015
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re
23RIESGO
abrir
Exploit-DB
Watchguard XCS 10.0 - Multiple Vulnerabilities
CVE-2015-5452webappsphp30 jun 2015
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RIESGO
abrir
anteriorpágina 190 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.