Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
GitHub PoC3
Crash PoC
CVE-2015-808809 dic 2015
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RIESGO
abrir
Exploit-DB
Microsoft Windows Media Center Library - Parsing Remote Code Execution aka 'self-executing' MCL File
CVE-2015-6131remotewindows09 dic 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
35RIESGO
abrir
Exploit-DB
Apple Mac OSX 10.11 - FTS Deep Structure of the FileSystem Buffer Overflow
CVE-2015-7039dososx09 dic 2015
Buffer overflow in libc in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office / COM Object - 'els.dll' DLL Planting (MS15-134)
CVE-2015-6128remotewindows09 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - '.Link' File Incorrectly Resolved Reference (MS15-134)
CVE-2015-6127remotewindows09 dic 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RIESGO
abrir
Metasploit300
MS15-134 Microsoft Windows Media Center MCL Information Disclosure
CVE-2015-612708 dic 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-6133localwindows08 dic 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-0041localwindows08 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2015-613308 dic 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511
50RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2015-612808 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-3235HIGHbajo ataque08 dic 2015
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-6132localwindows08 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-004108 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2015-613208 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-010008 dic 2015
Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges v
50RIESGO
abrir
Exploit-DBVexDay Proof
Atlassian HipChat for Jira Plugin - Velocity Template Injection (Metasploit)
CVE-2015-5603remotemultiple08 dic 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-3235HIGHbajo ataquelocalwindows08 dic 2015
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-0100localwindows08 dic 2015
Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges v
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-6128localwindows08 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RIESGO
abrir
GitHub PoC17
Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another Stagefright vulnerability, the integer overflow (CVE-2015-3864).
CVE-2015-386408 dic 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Metasploit300
Windows WMI Receive Notification Exploit
CVE-2016-0040HIGHbajo ataque04 dic 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
Exploit-DB
WordPress Plugin Gwolle Guestbook 1.5.3 - Remote File Inclusion
CVE-2015-8351webappsphp03 dic 2015
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_includ
35RIESGO
abrir
Exploit-DBVexDay Proof
Oracle BeeHive 2 - 'voice-servlet processEvaluation()' Write File (Metasploit)
CVE-2010-4417remotewindows03 dic 2015
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RIESGO
abrir
Metasploit300
Easy File Sharing HTTP Server 7.2 SEH Overflow
CVE-2018-905902 dic 2015
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Exploit-DBVexDay Proof
Man-db 2.6.7.1 - Local Privilege Escalation
CVE-2015-1336locallinux02 dic 2015
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t
23RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotecgi02 dic 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-7196remotecgi02 dic 2015
20RIESGO
abrir
Exploit-DB
Acunetix WVS 10 - Local Privilege Escalation
CVE-2015-4027localwindows02 dic 2015
The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users t
23RIESGO
abrir
Metasploit600
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque01 dic 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation
CVE-2015-5287HIGHbajo ataquelocallinux01 dic 2015
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir
anteriorpágina 1030 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.