Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DB
NetUSB - Kernel Stack Buffer Overflow
CVE-2015-3036doshardware29 oct 2015
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir
Exploit-DBVexDay Proof
Samsung - SecEmailComposer QUICK_REPLY_BACKGROUND Permissions
CVE-2015-7889dosandroid28 oct 2015
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RIESGO
abrir
Exploit-DBVexDay Proof
Samsung SecEmailUI - Script Injection
CVE-2015-7893remoteandroid28 oct 2015
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS
23RIESGO
abrir
Exploit-DBVexDay Proof
JIRA and HipChat for JIRA Plugin - Velocity Template Injection
CVE-2015-5603webappsjava28 oct 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir
Metasploit600
Atlassian HipChat for Jira Plugin Velocity Template Injection
CVE-2015-560328 oct 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir
Exploit-DBVexDay Proof
Samsung - 'm2m1shot' Kernel Driver Buffer Overflow
CVE-2015-7892dosandroid28 oct 2015
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RIESGO
abrir
Exploit-DBVexDay Proof
Samsung - 'seiren' Kernel Driver Buffer Overflow
CVE-2015-7890dosandroid28 oct 2015
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RIESGO
abrir
Exploit-DBVexDay Proof
Samsung fimg2d - FIMG2D_BITBLT_BLIT ioctl Concurrency Flaw
CVE-2015-7891dosandroid28 oct 2015
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation (Metasploit)
CVE-2015-5889localosx27 oct 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir
GitHub PoC23
Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents
CVE-2015-1641HIGHbajo ataque27 oct 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Comp
93RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari - User-Assisted Applescript Exec Attack (Metasploit)
CVE-2015-7007remoteosx26 oct 2015
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RIESGO
abrir
Metasploit600
Joomla Content History SQLi Remote Code Execution
CVE-2015-785823 oct 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Metasploit600
Joomla Content History SQLi Remote Code Execution
CVE-2015-729723 oct 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Metasploit600
Joomla Content History SQLi Remote Code Execution
CVE-2015-785723 oct 2015
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir
GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
CVE-2014-0160HIGHbajo ataque23 oct 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Realtyna RPL 8.9.2 - Multiple SQL Injections
CVE-2015-7714webappsphp23 oct 2015
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Realtyna RPL 8.9.2 - Persistent Cross-Site Scripting / Cross-Site Request Forgery
CVE-2015-7715webappsphp23 oct 2015
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RIESGO
abrir
Exploit-DBVexDay Proof
The World Browser 3.0 Final - Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows22 oct 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Metasploit300
Joomla com_contenthistory Error-Based SQL Injection
CVE-2015-729722 oct 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Exploit-DBVexDay Proof
Zpanel - Remote Code Execution (Metasploit)
CVE-2013-2097remotephp21 oct 2015
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir
Exploit-DBVexDay Proof
HTML Compiler - Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows20 oct 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - 'IExternalizable.writeExternal' Type Confusion
CVE-2015-7645HIGHbajo ataqueransomwaredosmultiple19 oct 2015
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RIESGO
abrir
Exploit-DB
Belkin N150 Router 1.00.08/1.00.09 - Directory Traversal
CVE-2014-2962webappshardware19 oct 2015
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware befor
50RIESGO
abrir
Exploit-DBVexDay Proof
Nibbleblog 4.0.3 - Arbitrary File Upload (Metasploit)
CVE-2015-6967remotephp19 oct 2015
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir
Metasploit0
Safari User-Assisted Applescript Exec Attack
CVE-2015-700716 oct 2015
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111)
CVE-2015-2553localwindows15 oct 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
CVE-2015-1635CRITICALbajo ataque14 oct 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALbajo ataque14 oct 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DB
ZYXEL PMG5318-B20A - OS Command Injection
CVE-2015-6018webappshardware14 oct 2015
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attac
28RIESGO
abrir
Exploit-DB
Linux/MIPS Kernel 2.6.36 - 'NetUSB' Remote Code Execution
CVE-2015-3036remotemultiple14 oct 2015
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir
anteriorpágina 1033 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.