Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
CVE-2005-2113webappsphp29 jun 2015
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote att
23RIESGO
abrir
Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
CVE-2005-2112webappsphp29 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
CVE-2015-4553webappsphp29 jun 2015
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RIESGO
abrir
Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection
CVE-2015-5082remotecgi29 jun 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection (Metasploit)
CVE-2015-5082remotecgi29 jun 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Exploit-DBVexDay Proof
Havij - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows27 jun 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DB
ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
CVE-2015-2169webappswindows26 jun 2015
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Multiple SQL Injections
CVE-2015-4633webappsphp26 jun 2015
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
CVE-2015-4631webappsphp26 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir
Exploit-DB
Thycotic Secret Server 8.8.000004 - Persistent Cross-Site Scripting
CVE-2015-3443webappsmultiple26 jun 2015
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
CVE-2015-4630webappsphp26 jun 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RIESGO
abrir
Exploit-DB
Koha 3.20.1 - Directory Traversal
CVE-2015-4632webappsphp26 jun 2015
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
CVE-2015-3221webappsphp24 jun 2015
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, a
28RIESGO
abrir
Exploit-DBVexDay Proof
Vesta Control Panel 0.9.8 - OS Command Injection
CVE-2015-4117webappsphp24 jun 2015
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
CVE-2015-1701HIGHbajo ataqueransomwarelocalwindows24 jun 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ShaderJob Buffer Overflow (Metasploit)
CVE-2015-3090remotemultiple24 jun 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.3 - 'register.php' SQL Injection
CVE-2015-3933webappsphp24 jun 2015
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
CVE-2015-5066webappsphp24 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3112doswindows23 jun 2015
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3111doswindows23 jun 2015
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.gif' Parsing Memory Corruption
CVE-2015-3110doswindows23 jun 2015
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex
28RIESGO
abrir
Exploit-DBVexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
CVE-2015-1158remotemultiple22 jun 2015
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir
Exploit-DBVexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
CVE-2007-3071webappswindows19 jun 2015
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RIESGO
abrir
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5149webappsmultiple19 jun 2015
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RIESGO
abrir
Exploit-DBVexDay Proof
Lively Cart - SQL Injection
CVE-2015-5148webappsmultiple19 jun 2015
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RIESGO
abrir
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5150webappsmultiple19 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RIESGO
abrir
Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
CVE-2015-5079webappsphp17 jun 2015
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
CVE-2015-1328locallinux16 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
CVE-2015-1328locallinux16 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails 4.0.x/4.1.x/4.2.x (Web Console v2) - Whitelist Bypass Code Execution (Metasploit)
CVE-2015-3224remotemultiple16 jun 2015
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
anteriorpágina 191 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.