Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
CVE-2014-0980localwindows19 mar 2015
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DB
Citrix Nitro SDK - Command Injection
CVE-2015-2838webappslinux19 mar 2015
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote
23RIESGO
abrir
Exploit-DB
Citrix Command Center - Credential Disclosure
CVE-2015-2682webappsxml19 mar 2015
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RIESGO
abrir
Exploit-DBVexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
CVE-2015-0235remotelinux18 mar 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
Websense Appliance Manager - Command Injection
CVE-2015-2746webappsjava18 mar 2015
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON
28RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet Single Sign On - Stack Overflow
CVE-2015-2281doswindows18 mar 2015
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
CVE-2015-0318remotewindows17 mar 2015
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir
Exploit-DB
Moodle 2.5.9/2.6.8/2.7.5/2.8.3 - Block Title Handler Cross-Site Scripting
CVE-2015-2269webappsphp17 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.
23RIESGO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2314webappsphp16 mar 2015
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
CVE-2015-1427CRITICALbajo ataqueremotejava16 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Exploit-DBVexDay Proof
IPass Control Pipe - Remote Command Execution (Metasploit)
CVE-2015-0925remotewindows16 mar 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
CVE-2015-2292webappsphp16 mar 2015
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RIESGO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2315webappsphp16 mar 2015
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir
Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
CVE-2015-2791webappsphp16 mar 2015
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts
28RIESGO
abrir
Exploit-DB
Foxit Reader 7.0.6.1126 - Unquoted Service Path Privilege Escalation
CVE-2015-2789localwindows16 mar 2015
Unquoted Windows search path vulnerability in the Foxit Cloud Safe Update Service in the Cloud plugin in Foxit Reader 6.
23RIESGO
abrir
Exploit-DB
Intel Network Adapter Diagnostic Driver - IOCTL Handling
CVE-2015-2291HIGHbajo ataqueransomwaredoswindows14 mar 2015
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
Exploit-DB
WoltLab Community Gallery - Persistent Cross-Site Scripting
CVE-2015-2275webappsphp13 mar 2015
Cross-site scripting (XSS) vulnerability in WoltLab Community Gallery 2.0 before 2014-12-26 allows remote attackers to i
23RIESGO
abrir
Exploit-DB
ArcSight Logger - Arbitrary File Upload / Code Execution
CVE-2014-7884remotelinux13 mar 2015
Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated att
28RIESGO
abrir
Exploit-DB
Citrix Netscaler NS10.5 - WAF Bypass (Via HTTP Header Pollution)
CVE-2015-2841webappsxml12 mar 2015
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restriction
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray UncompressViaZlibVariant Use-After-Free (Metasploit)
CVE-2015-0311HIGHbajo ataqueremotewindows12 mar 2015
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RIESGO
abrir
Exploit-DB
Ubuntu 15.04 (Development) - 'Upstart' Logrotation Privilege Escalation
CVE-2015-2285locallinux12 mar 2015
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2-0ubuntu9, as used in Ubuntu
23RIESGO
abrir
Exploit-DB
Foxit Products GIF Conversion - 'DataSubBlock' Memory Corruption
CVE-2015-2790doswindows11 mar 2015
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir
Exploit-DB
Foxit Products GIF Conversion - 'LZWMinimumCodeSize' Memory Corruption
CVE-2015-2790doswindows11 mar 2015
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2015-1427CRITICALbajo ataqueremotelinux11 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
CVE-2015-0081doswindows11 mar 2015
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RIESGO
abrir
Exploit-DB
CS-Cart 4.2.4 - Cross-Site Request Forgery
CVE-2015-2701webappsphp11 mar 2015
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RIESGO
abrir
Exploit-DB
CodoForum 2.5.1 - Arbitrary File Download
CVE-2014-9261webappsphp10 mar 2015
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2680webappsphp10 mar 2015
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2679webappsphp10 mar 2015
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RIESGO
abrir
Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
CVE-2015-2678webappsphp10 mar 2015
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RIESGO
abrir
anteriorpágina 199 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.