Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
CVE-2015-4063webappsphp26 may 2015
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPres
38RIESGO
abrir
Exploit-DBVexDay Proof
Sendio ESP - Information Disclosure
CVE-2014-0999webappsjsp26 may 2015
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RIESGO
abrir
Exploit-DBVexDay Proof
Fuse 2.9.3-15 - Local Privilege Escalation
CVE-2015-3202locallinux23 may 2015
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as ro
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin FeedWordPress 2015.0426 - SQL Injection
CVE-2015-4018webappsphp20 may 2015
SQL injection vulnerability in feedwordpresssyndicationpage.class.php in the FeedWordPress plugin before 2015.0514 for W
23RIESGO
abrir
Exploit-DBVexDay Proof
Phoenix Contact ILC 150 ETH PLC - Remote Control Script
CVE-2014-9195remotehardware20 may 2015
Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
85RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.0/8.1 (x64) - 'TrackPopupMenu' Local Privilege Escalation (MS14-058)
CVE-2014-4113HIGHbajo ataquelocalwindows_x86-6419 may 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1701HIGHbajo ataqueransomwarelocalwindows18 may 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1676localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1679localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1678localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1677localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1680localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - domainMemory ByteArray Use-After-Free (Metasploit)
CVE-2015-0359remotewindows08 may 2015
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - NetConnection Type Confusion (Metasploit)
CVE-2015-0336remotewindows08 may 2015
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir
Exploit-DBVexDay Proof
Novell ZENworks Configuration Management - Arbitrary File Upload (Metasploit)
CVE-2015-0779remotejava08 may 2015
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin RevSlider 3.0.95 - Arbitrary File Upload / Execution (Metasploit)
CVE-2014-9735remotephp08 may 2015
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - UncompressViaZlibVariant Uninitialized Memory (Metasploit)
CVE-2014-8440remotewindows01 may 2015
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 4.2 - Persistent Cross-Site Scripting
CVE-2015-3440webappsphp27 abr 2015
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i
28RIESGO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 2.8 (Windows 7) - '.wav' File Buffer Overflow (SEH) (DEP Bypass)
CVE-2011-5165localwindows24 abr 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 2.8 - '.wav' File Buffer Overflow (SEH)
CVE-2011-5165localwindows23 abr 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2844webappsphp21 abr 2015
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1420434000 allows remote attackers to execute arb
28RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2845webappsphp21 abr 2015
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RIESGO
abrir
Exploit-DBVexDay Proof
BlueDragon CFChart Servlet 7.1.1.17759 - Arbitrary File Retrieval/Deletion
CVE-2014-5370webappscfm21 abr 2015
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDra
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2842webappsphp21 abr 2015
Unrestricted file upload vulnerability in go_audiostore.php in the audiostore (Voice Files) upload functionality in GoAu
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - copyPixelsToByteArray Integer Overflow (Metasploit)
CVE-2014-0556remotewindows21 abr 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Creative Contact Form - Arbitrary File Upload (Metasploit)
CVE-2014-8739remotephp21 abr 2015
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Reflex Gallery - Arbitrary File Upload (Metasploit)
CVE-2015-4133remotephp21 abr 2015
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3-1406088000 - Authentication Bypass / Arbitrary File Upload / Command Injection
CVE-2015-2843webappsphp21 abr 2015
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir
Exploit-DBVexDay Proof
Abrt (Fedora 21) - Race Condition
CVE-2015-1862locallinux14 abr 2015
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot
23RIESGO
abrir
Exploit-DBVexDay Proof
Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation
CVE-2015-1318locallinux14 abr 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.