Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
ProFTPD 1.3.5 Mod_Copy Command Execution
CVE-2015-330622 abr 2015
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Metasploit600
GoAutoDial 3.3 Authentication Bypass / Command Injection
CVE-2015-284521 abr 2015
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RIESGO
abrir
Metasploit600
GoAutoDial 3.3 Authentication Bypass / Command Injection
CVE-2015-284321 abr 2015
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir
Metasploit600
ABRT raceabrt Privilege Escalation
CVE-2015-331514 abr 2015
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RIESGO
abrir
Metasploit600
Lenovo System Update Privilege Escalation
CVE-2015-221912 abr 2015
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allo
38RIESGO
abrir
Metasploit600
Wordpress N-Media Website Contact Form Upload Vulnerability
CVE-2015-10137CRITICAL12 abr 2015
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RIESGO
abrir
Metasploit500
Apple OS X Rootpipe Privilege Escalation
CVE-2015-1130HIGHbajo ataque09 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir
Metasploit300
Archer C7 Directory Traversal Vulnerability
CVE-2015-3035HIGHbajo ataque08 abr 2015
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before
100RIESGO
abrir
Metasploit300
Apple OSX/iOS/Windows Safari Non-HTTPOnly Cookie Theft
CVE-2015-112608 abr 2015
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not
18RIESGO
abrir
Metasploit600
Novell ZENworks Configuration Management Arbitrary File Upload
CVE-2015-077907 abr 2015
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RIESGO
abrir
Metasploit600
Ceragon FibeAir IP-10 SSH Private Key Exposure
CVE-2015-093601 abr 2015
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RIESGO
abrir
Metasploit600
Apport / ABRT chroot Privilege Escalation
CVE-2015-131831 mar 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir
Metasploit0
Firefox PDF.js Privileged Javascript Injection
CVE-2015-081631 mar 2015
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RIESGO
abrir
Metasploit300
Airties login-cgi Buffer Overflow
CVE-2015-279731 mar 2015
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir
Metasploit0
Firefox PDF.js Privileged Javascript Injection
CVE-2015-080231 mar 2015
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir
Metasploit300
Web-Dorado ECommerce WD for Joomla! search_category_id SQL Injection Scanner
CVE-2015-256220 mar 2015
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir
Metasploit600
Wordpress Work The Flow Upload Vulnerability
CVE-2015-10138CRITICAL14 mar 2015
Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload
63RIESGO
abrir
Metasploit600
Solarwinds Firewall Security Manager 6.6.5 Client Session Handling Vulnerability
CVE-2015-228413 mar 2015
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privile
60RIESGO
abrir
Metasploit500
Adobe Flash Player NetConnection Type Confusion
CVE-2015-033612 mar 2015
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir
Metasploit600
iPass Mobile Client Service Privilege Escalation
CVE-2015-092512 mar 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir
Metasploit600
Microsoft Windows Shell LNK Code Execution
CVE-2015-009610 mar 2015
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir
Metasploit600
Microsoft Windows Shell LNK Code Execution
CVE-2015-009610 mar 2015
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir
Metasploit600
WordPress WPshop eCommerce Arbitrary File Upload Vulnerability
CVE-2015-10135CRITICAL09 mar 2015
WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
43RIESGO
abrir
Metasploit600
PHPMoAdmin 1.1.2 Remote Code Execution
CVE-2015-220803 mar 2015
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir
Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
CVE-2014-858603 mar 2015
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir
Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CVE-2014-868701 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir
Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CVE-2014-868401 mar 2015
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir
Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CVE-2014-868601 mar 2015
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir
Metasploit300
D-Link/TRENDnet NCC Service Command Injection
CVE-2015-1187CRITICALbajo ataque26 feb 2015
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir
Metasploit300
WordPress WP EasyCart Plugin Privilege Escalation
CVE-2015-267325 feb 2015
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.