Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.106exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Rowhammer - NaCl Sandbox Escape
CVE-2015-3693locallinux_x86-6409 mar 2015
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates fo
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (x86-64) - Rowhammer Privilege Escalation
CVE-2015-0565locallinux_x86-6409 mar 2015
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir
Exploit-DBVexDay Proof
Rowhammer - NaCl Sandbox Escape
CVE-2015-0565locallinux_x86-6409 mar 2015
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector 8.10 - Remote Command Execution (Metasploit)
CVE-2014-2623remotewindows06 mar 2015
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8684remotephp04 mar 2015
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8687remotephp04 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8686remotephp04 mar 2015
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
CVE-2014-7285remotelinux04 mar 2015
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
CVE-2014-9463webappsphp02 mar 2015
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RIESGO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
CVE-2014-8687webappshardware01 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir
Exploit-DBVexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
CVE-2015-1187CRITICALbajo ataquewebappslinux26 feb 2015
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir
Exploit-DBVexDay Proof
HP Client - Automation Command Injection (Metasploit)
CVE-2015-1497remotemultiple24 feb 2015
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Exploit-DBVexDay Proof
Publish-It 3.6d - Local Buffer Overflow (SEH)
CVE-2014-0980localwindows18 feb 2015
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir
Exploit-DBVexDay Proof
Java JMX - Server Insecure Configuration Java Code Execution (Metasploit)
CVE-2015-2342remotejava17 feb 2015
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Fancybox 3.0.2 - Persistent Cross-Site Scripting
CVE-2015-1494webappsphp16 feb 2015
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL Injection
CVE-2015-2196webappsphp13 feb 2015
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ
43RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Theme Holding Pattern - Arbitrary File Upload (Metasploit)
CVE-2015-1172webappslinux11 feb 2015
Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a
50RIESGO
abrir
Exploit-DBVexDay Proof
SixApart MovableType < 5.2.12 - Storable Perl Code Execution (Metasploit)
CVE-2015-1592webappslinux11 feb 2015
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP EasyCart - Unrestricted Arbitrary File Upload (Metasploit)
CVE-2014-9308webappsphp10 feb 2015
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RIESGO
abrir
Exploit-DBVexDay Proof
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
CVE-2014-7883webappswindows03 feb 2015
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Remote Desktop Services - Web Proxy IE Sandbox Escape (MS15-004) (Metasploit)
CVE-2015-0016HIGHbajo ataquelocalwindows03 feb 2015
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector 8.x - Remote Command Execution
CVE-2014-2623remotehp-ux30 ene 2015
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
CVE-2014-7288remotewindows30 ene 2015
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Multiple Vulnerabilities
CVE-2014-8612dosfreebsd29 ene 2015
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Multiple Vulnerabilities
CVE-2014-0998dosfreebsd29 ene 2015
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1372webappsphp26 ene 2015
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1371webappsphp26 ene 2015
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code b
23RIESGO
abrir
Exploit-DBVexDay Proof
Android WiFi-Direct - Denial of Service
CVE-2014-0997dosandroid26 ene 2015
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1373webappsphp26 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inje
23RIESGO
abrir
Exploit-DBVexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
CVE-2015-1374webappsphp26 ene 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.