Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DB
libsndfile 1.0.25 - Local Heap Overflow
CVE-2015-7805localmultiple13 oct 2015
Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex val
28RIESGO
abrir
Exploit-DB
ZHONE < S3.0.501 - Multiple Vulnerabilities
CVE-2014-8357remotehardware13 oct 2015
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a
23RIESGO
abrir
Exploit-DB
ZHONE < S3.0.501 - Multiple Vulnerabilities
CVE-2014-9118remotehardware13 oct 2015
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary comm
35RIESGO
abrir
Exploit-DB
ZHONE < S3.0.501 - Multiple Vulnerabilities
CVE-2014-8356remotehardware13 oct 2015
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended a
23RIESGO
abrir
Exploit-DB
F5 Big-IP 10.2.4 Build 595.0 Hotfix HF3 - Directory Traversal
CVE-2015-4040webappshardware13 oct 2015
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 t
23RIESGO
abrir
Metasploit300
Limesurvey Unauthenticated File Download
CVE-2025-34120HIGH12 oct 2015
LimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup Payload
36RIESGO
abrir
Metasploit600
Wordpress Ajax Load More PHP Upload Vulnerability
CVE-2015-10140HIGH10 oct 2015
Ajax Load More < 2.8.1.2 - Subscriber+ File Upload & Deletion
36RIESGO
abrir
Exploit-DB
Kallithea 0.2.9 - 'came_from' HTTP Response Splitting
CVE-2015-5285webappsmultiple08 oct 2015
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc
23RIESGO
abrir
Exploit-DB
Zope Management Interface 4.3.7 - Cross-Site Request Forgery
CVE-2015-7293webappspython07 oct 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RIESGO
abrir
VulnCheck XDB
local
CVE-2015-363607 oct 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - 'uploader.aspx' Arbitrary File Upload (Metasploit)
CVE-2015-6922remotewindows05 oct 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir
Exploit-DBVexDay Proof
TrueCrypt 7 / VeraCrypt 1.13 - Drive Letter Symbolic Link Creation Privilege Escalation
CVE-2015-7358localwindows_x8605 oct 2015
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RIESGO
abrir
Metasploit300
ManageEngine ServiceDesk Plus Path Traversal
CVE-2011-275703 oct 2015
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir
Metasploit300
PDF Shaper Buffer Overflow
CVE-2025-34106HIGH03 oct 2015
PDF Shaper v3.5/3.6 Buffer Overflow via Convert to Image Feature
36RIESGO
abrir
Exploit-DB
ElasticSearch 1.6.0 - Arbitrary File Download
CVE-2015-5531webappslinux02 oct 2015
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation
CVE-2015-5889localosx01 oct 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir
Metasploit300
Mac OS X 10.9.5 / 10.10.5 - rsh/libmalloc Privilege Escalation
CVE-2015-588901 oct 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir
Metasploit300
Apache James Server 2.3.2 Insecure User Creation Arbitrary File Write
CVE-2015-761101 oct 2015
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RIESGO
abrir
Exploit-DB
Bosch Security Systems Dinion NBN-498 - Web Interface XML Injection
CVE-2015-6970webappshardware01 oct 2015
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows r
23RIESGO
abrir
GitHub PoC
gina-alaska/bash-cve-2014-7169-cookbook
CVE-2014-7169CRITICALbajo ataque30 sep 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-7169CRITICALbajo ataque30 sep 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir
Exploit-DB
Apport 2.19 (Ubuntu 15.04) - Local Privilege Escalation
CVE-2015-1338locallinux29 sep 2015
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly ga
23RIESGO
abrir
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
CVE-2015-6589webappsasp29 sep 2015
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RIESGO
abrir
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (2)
CVE-2015-6922webappsasp29 sep 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine EventLog Analyzer - Remote Code Execution (Metasploit)
CVE-2015-7387remotewindows29 sep 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Exploit-DB
PCMan FTP Server 2.0.7 - Directory Traversal
CVE-2015-7601remotewindows28 sep 2015
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..//
50RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7902webappsjsp28 sep 2015
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed
23RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-6493webappsjsp28 sep 2015
Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu
23RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-7904webappsjsp28 sep 2015
Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 al
23RIESGO
abrir
Exploit-DBVexDay Proof
Watchguard XCS - Remote Command Execution (Metasploit)
CVE-2015-5453remotebsd28 sep 2015
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RIESGO
abrir
anteriorpágina 1034 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.