Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DB
ntop-ng 2.0.151021 - Privilege Escalation
CVE-2015-8368webappsmultiple01 dic 2015
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u
23RIESGO
abrir
Exploit-DBVexDay Proof
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
CVE-2015-5273localmultiple01 dic 2015
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
CVE-2015-5287HIGHbajo ataquelocalmultiple01 dic 2015
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir
Metasploit600
Cambium ePMP1000 'ping' Shell via Command Injection (up to v2.5)
CVE-2017-525528 nov 2015
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir
Exploit-DBVexDay Proof
SAP Sybase Adaptive Server Enterprise - XML External Entity Information Disclosure
CVE-2013-6025remotemultiple25 nov 2015
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to re
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 5.x - Remote Code Execution
CVE-2015-7808webappsphp23 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Race Condition DestroySMWP Use-After-Free (MS15-115)
CVE-2015-6101doswindows23 nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DB
Oracle Outside In PDF 8.5.2 - Parsing Memory Corruption (1)
CVE-2015-4877doswindows23 nov 2015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir
Metasploit600
ABRT sosreport Privilege Escalation
CVE-2015-5287HIGHbajo ataque23 nov 2015
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir
Exploit-DB
Oracle Outside In PDF 8.5.2 - Parsing Memory Corruption (2)
CVE-2015-4878doswindows23 nov 2015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir
Exploit-DB
Acrobat Reader DC 15.008.20082.15957 - '.PDF' Parsing Memory Corruption
CVE-2015-7622doswindows23 nov 2015
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Device Contexts and NtGdiSelectBitmap Use-After-Free (MS15-115)
CVE-2015-6100doswindows23 nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Nvidia Stereoscopic 3D Driver Service 7.17.13.5382 - Arbitrary Run Key Creation
CVE-2015-7865localwindows23 nov 2015
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7857remotephp23 nov 2015
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Cursor Object Memory Leak (MS15-115)
CVE-2015-6102doswindows23 nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7858remotephp23 nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ndis.sys' IOCTL 0x170034 (ndis!ndisNsiGetIfNameForIfIndex) Pool Buffer Overflow (MS15-117)
CVE-2015-6098doswindows23 nov 2015
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows S
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7297remotephp23 nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
GitHub PoC5
Estudo e apresentação do bug CVE-2014-4943 para a disciplina MAC0448
CVE-2014-494322 nov 2015
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7248webappshardware20 nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7249webappshardware20 nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access r
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7251webappshardware20 nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, whic
28RIESGO
abrir
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7250webappshardware20 nov 2015
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE
28RIESGO
abrir
Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
CVE-2015-7258webappshardware20 nov 2015
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RIESGO
abrir
Exploit-DBVexDay Proof
Chkrootkit - Local Privilege Escalation (Metasploit)
CVE-2014-0476locallinux20 nov 2015
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-8703webappshardware20 nov 2015
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authe
23RIESGO
abrir
Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
CVE-2015-7259webappshardware20 nov 2015
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RIESGO
abrir
Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
CVE-2015-7252webappshardware20 nov 2015
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_
23RIESGO
abrir
Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
CVE-2015-7257webappshardware20 nov 2015
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RIESGO
abrir
Exploit-DBVexDay Proof
F5 iControl - 'iCall::Script' Root Command Execution (Metasploit)
CVE-2015-3628remotehardware19 nov 2015
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
anteriorpágina 1031 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.