Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
WordPress Contus Video Gallery Unauthenticated SQL Injection Scanner
CVE-2015-206524 feb 2015
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir
Metasploit300
Solarwinds Orion AccountManagement.asmx GetAccounts Admin Creation
CVE-2014-956624 feb 2015
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir
Metasploit500
D-Link DCS-931L File Upload
CVE-2015-204923 feb 2015
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir
Metasploit300
D-Link Devices HNAP SOAPAction-Header Command Execution
CVE-2015-2051HIGHbajo ataque13 feb 2015
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RIESGO
abrir
Metasploit600
Maarch LetterBox Unrestricted File Upload
CVE-2015-158711 feb 2015
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RIESGO
abrir
Metasploit400
SixApart MovableType Storable Perl Code Execution
CVE-2015-159211 feb 2015
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use
60RIESGO
abrir
Metasploit600
ElasticSearch Search Groovy Sandbox Bypass
CVE-2015-1427CRITICALbajo ataque11 feb 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Metasploit600
WordPress Holding Pattern Theme Arbitrary File Upload
CVE-2015-117211 feb 2015
Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a
50RIESGO
abrir
Metasploit300
WordPress WPLMS Theme Privilege Escalation
CVE-2015-10139HIGH09 feb 2015
WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation
36RIESGO
abrir
Metasploit600
Ektron 8.5, 8.7, 9.0 XSLT Transform Remote Code Execution
CVE-2015-092305 feb 2015
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before
23RIESGO
abrir
Metasploit500
Adobe Flash Player ByteArray With Workers Use After Free
CVE-2015-0313HIGHbajo ataque02 feb 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir
Metasploit300
MS15-018 Microsoft Internet Explorer 10 and 11 Cross-Domain JavaScript Injection
CVE-2015-007201 feb 2015
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass t
60RIESGO
abrir
Metasploit300
X360 VideoPlayer ActiveX Control Buffer Overflow
CVE-2025-34128HIGH30 ene 2015
X360 VideoPlayer ActiveX Control Buffer Overflow via ConvertFile()
36RIESGO
abrir
Metasploit300
ManageEngine Multiple Products Arbitrary File Download
CVE-2014-786328 ene 2015
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir
Metasploit300
ManageEngine Multiple Products Arbitrary Directory Listing
CVE-2014-786328 ene 2015
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir
Metasploit600
Oracle Weblogic Server Deserialization RCE - Raw Object
CVE-2015-4852CRITICALbajo ataque28 ene 2015
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
Metasploit500
Exim GHOST (glibc gethostbyname) Buffer Overflow
CVE-2015-023527 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Metasploit600
IPass Control Pipe Remote Command Execution
CVE-2015-092521 ene 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir
Metasploit600
WordPress Platform Theme File Upload Vulnerability
CVE-2015-10143CRITICAL21 ene 2015
Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update
43RIESGO
abrir
Metasploit300
Java Secure Socket Extension (JSSE) SKIP-TLS MITM Proxy
CVE-2014-659320 ene 2015
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.
50RIESGO
abrir
Metasploit600
WordPress Pixabay Images PHP Code Upload
CVE-2015-137619 ene 2015
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RIESGO
abrir
Metasploit400
MS15-004 Microsoft Remote Desktop Services Web Proxy IE Sandbox Escape
CVE-2015-0016HIGHbajo ataque13 ene 2015
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir
Metasploit600
WordPress WP EasyCart Unrestricted File Upload
CVE-2014-930808 ene 2015
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RIESGO
abrir
Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
CVE-2015-092106 ene 2015
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x
23RIESGO
abrir
Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
CVE-2015-092206 ene 2015
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers'
23RIESGO
abrir
Metasploit600
ASUS infosvr Auth Bypass Command Execution
CVE-2014-958304 ene 2015
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir
Metasploit300
ManageEngine Desktop Central Administrator Account Creation
CVE-2014-786231 dic 2014
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RIESGO
abrir
Metasploit300
Achat Unicode SEH Buffer Overflow
CVE-2025-34127CRITICAL18 dic 2014
Achat v0.150 SEH Buffer Overflow via UDP
63RIESGO
abrir
Metasploit600
Malicious Git and Mercurial HTTP Server For CVE-2014-9390
CVE-2014-939018 dic 2014
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS
40RIESGO
abrir
Metasploit300
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Scanner
CVE-2014-922217 dic 2014
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re
30RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.