Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DBVexDay Proof
Adobe Flash GradientFill - Use-After-Frees
CVE-2015-8043doswindows17 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir
Metasploit300
Symantec Messaging Gateway 10 Exposure of Stored AD Password Vulnerability
CVE-2016-220317 dic 2015
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RIESGO
abrir
Exploit-DBVexDay Proof
win32k Clipboard Bitmap - Use-After-Free
CVE-2015-6173doswindows_x8617 dic 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.gridFitType Setter - Use-After-Free
CVE-2015-7652doswindows17 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.antiAliasType Setter - Use-After-Free
CVE-2015-8046doswindows17 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - addresses_equal 'dissect_rsvp_common' Use-After-Free
CVE-2015-8727dosmultiple16 dic 2015
The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - ascend_seek Static Out-of-Bounds Read
CVE-2015-8729dosmultiple16 dic 2015
The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x b
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - dissct_rsl_ipaccess_msg Static Out-of-Bounds Read
CVE-2015-8731dosmultiple16 dic 2015
The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.1
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
CVE-2015-8725dosmultiple16 dic 2015
The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - my_dgt_tbcd_unpack Static Buffer Overflow
CVE-2015-8728dosmultiple16 dic 2015
The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - file_read 'wtap_read_bytes_or_eof/mp2t_find_next_pcr' Stack Buffer Overflow
CVE-2015-8736dosmultiple16 dic 2015
The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reser
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - memcpy 'get_value / dissect_btatt' SIGSEGV
CVE-2015-8735dosmultiple16 dic 2015
The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
CVE-2015-8740dosmultiple16 dic 2015
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x befo
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - dissect_nbap_MACdPDU_Size SIGSEGV
CVE-2015-8730dosmultiple16 dic 2015
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not va
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - find_signature Stack Out-of-Bounds Read
CVE-2015-8726dosmultiple16 dic 2015
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate cer
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - wmem_alloc Assertion Failure
CVE-2015-8739dosmultiple16 dic 2015
The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 imp
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - dissect_zcl_pwr_prof_pwrprofstatersp Static Out-of-Bounds Read
CVE-2015-8732dosmultiple16 dic 2015
The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissect
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - AirPDcapPacketProcess Stack Buffer Overflow
CVE-2015-8723dosmultiple16 dic 2015
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 an
23RIESGO
abrir
Metasploit300
IBM Tivoli Storage Manager FastBack Server Opcode 0x534 Denial of Service
CVE-2015-193015 dic 2015
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attacke
18RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 1.5 < 3.4.5 - Object Injection Remote Command Execution
CVE-2015-8562webappsphp15 dic 2015
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins CLI - RMI Java Deserialization (Metasploit)
CVE-2015-8103remotejava15 dic 2015
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine Desktop Central 9 - FileUploadServlet ConnectionId (Metasploit)
CVE-2015-8249remotejsp15 dic 2015
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RIESGO
abrir
Exploit-DB
Bitrix bitrix.xscan Module 1.0.3 - Directory Traversal
CVE-2015-8357webappsphp14 dic 2015
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in Serialization with ObjectEncoder.dynamicPropertyWriter
CVE-2015-7648dosmultiple14 dic 2015
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RIESGO
abrir
Exploit-DB
Bitrix bitrix.mpbuilder Module 1.0.10 - Local File Inclusion
CVE-2015-8358webappsphp14 dic 2015
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - MSHTML!CObjectElement Use-After-Free (MS15-124)
CVE-2015-6152doswindows14 dic 2015
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office / COM Object - DLL Planting with 'comsvcs.dll' Delay Load of 'mqrt.dll' (MS15-132)
CVE-2015-6132remotewindows14 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir
Metasploit600
ManageEngine Desktop Central 9 FileUploadServlet ConnectionId Vulnerability
CVE-2015-824914 dic 2015
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RIESGO
abrir
Metasploit600
Joomla HTTP Header Unauthenticated Remote Code Execution
CVE-2015-856214 dic 2015
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in IExternalizable.readExternal When Performing Local Serialization
CVE-2015-7647dosmultiple14 dic 2015
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RIESGO
abrir
anteriorpágina 1029 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.