Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
RedaxScript CMS 2.2.0 - SQL Injection
CVE-2015-1518webappsphp09 feb 2015
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RIESGO
abrir
Exploit-DB
Fork CMS 3.8.5 - SQL Injection
CVE-2015-1467webappsphp09 feb 2015
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to exec
23RIESGO
abrir
Exploit-DB
u5CMS 3.9.3 - 'deletefile.php' Arbitrary File Deletion
CVE-2015-1577webappsphp09 feb 2015
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RIESGO
abrir
Exploit-DB
u5CMS 3.9.3 - Multiple SQL Injections
CVE-2015-1576webappsphp09 feb 2015
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DB
ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities
CVE-2014-7864webappsmultiple09 feb 2015
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan
28RIESGO
abrir
Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
CVE-2015-1578remotewindows08 feb 2015
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir
Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
CVE-2015-1577remotewindows08 feb 2015
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RIESGO
abrir
Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
CVE-2015-2067webappsphp05 feb 2015
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento
50RIESGO
abrir
Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
CVE-2015-2068webappsphp05 feb 2015
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server a
43RIESGO
abrir
Exploit-DB
AVG Internet Security 2015.0.5315 - Arbitrary Write Privilege Escalation
CVE-2014-9632localwindows04 feb 2015
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec
23RIESGO
abrir
Exploit-DB
K7 Computing (Multiple Products) - Arbitrary Write Privilege Escalation
CVE-2014-9643localwindows04 feb 2015
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users
23RIESGO
abrir
Exploit-DB
BullGuard (Multiple Products) - Arbitrary Write Privilege Escalation
CVE-2014-9642localwindows04 feb 2015
bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca
23RIESGO
abrir
Exploit-DB
Pragyan CMS 3.0 - SQL Injection
CVE-2015-1471webappsphp04 feb 2015
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
CVE-2014-7883webappswindows03 feb 2015
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o
35RIESGO
abrir
Exploit-DB
ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery
CVE-2014-9331webappsmultiple03 feb 2015
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Remote Desktop Services - Web Proxy IE Sandbox Escape (MS15-004) (Metasploit)
CVE-2015-0016HIGHbajo ataquelocalwindows03 feb 2015
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir
Exploit-DB
Sefrengo CMS 1.6.1 - Multiple SQL Injections
CVE-2015-1428webappsphp02 feb 2015
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DB
Symantec Altiris Agent 6.9 (Build 648) - Local Privilege Escalation
CVE-2014-7286localwindows01 feb 2015
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local us
23RIESGO
abrir
Exploit-DB
Trend Micro 8.0.1133 (Multiple Products) - Local Privilege Escalation
CVE-2014-9641localwindows31 ene 2015
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RIESGO
abrir
Exploit-DB
McAfee Data Loss Prevention Endpoint - Arbitrary Write Privilege Escalation
CVE-2015-1305localwindows30 ene 2015
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, an
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector 8.x - Remote Command Execution
CVE-2014-2623remotehp-ux30 ene 2015
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
CVE-2014-7288remotewindows30 ene 2015
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2003 SP2 - Local Privilege Escalation (MS14-070)
CVE-2014-4076localwindows29 ene 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
CVE-2012-4889webappshardware29 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RIESGO
abrir
Exploit-DB
Apple Mac OSX < 10.10.x - GateKeeper Bypass
CVE-2014-8826localosx29 ene 2015
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RIESGO
abrir
Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
CVE-2012-4891webappshardware29 ene 2015
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Multiple Vulnerabilities
CVE-2014-8612dosfreebsd29 ene 2015
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Multiple Vulnerabilities
CVE-2014-0998dosfreebsd29 ene 2015
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows
23RIESGO
abrir
Exploit-DB
Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
CVE-2015-0235doslinux29 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
CVE-2015-1477webappsmultiple26 ene 2015
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execu
23RIESGO
abrir
anteriorpágina 202 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.