Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-6009webappsphp23 sep 2015
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to e
23RIESGO
abrir
Metasploit300
Kaseya VSA Master Administrator Account Creation
CVE-2015-692223 sep 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir
Metasploit600
Kaseya VSA uploader.aspx Arbitrary File Upload
CVE-2015-692223 sep 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir
Metasploit300
Konica Minolta FTP Utility 1.00 Directory Traversal Information Disclosure
CVE-2015-760322 sep 2015
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RIESGO
abrir
Exploit-DBVexDay Proof
Apple qlmanage - SceneKit::daeElement::setElementName Heap Overflow
CVE-2015-3783dososx22 sep 2015
SceneKit in Apple OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (me
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'HmgAllocateObjectAttr' Use-After-Free (MS15-061)
CVE-2015-1726doswindows_x8622 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Use-After-Free with Cursor Object (MS15-097)
CVE-2015-2517doswindows_x8622 sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Regex Engine (TRE) - Integer Signedness / Overflow
CVE-2015-3798dososx22 sep 2015
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Regex Engine (TRE) - Stack Buffer Overflow (PoC)
CVE-2015-3796dososx22 sep 2015
The TRE library in Libc in Apple iOS before 8.4.1 and OS X before 10.10.5 allows context-dependent attackers to execute
28RIESGO
abrir
Exploit-DB
h5ai < 0.25.0 - Unrestricted Arbitrary File Upload
CVE-2015-3203webappsphp22 sep 2015
Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'FlashWindowEx​' Memory Corruption (MS15-097)
CVE-2015-2511doswindows_x8622 sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Brush Object Use-After-Free (MS15-061)
CVE-2015-1724doswindows22 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Null Pointer Dereference with Window Station and Clipboard (MS15-061)
CVE-2015-1721doswindows_x8622 sep 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RIESGO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.0 - Directory Traversal
CVE-2015-7603remotewindows22 sep 2015
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'bGetRealizedBrush' Use-After-Free (MS15-097)
CVE-2015-2518doswindows_x8622 sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'SURFOBJ' Null Pointer Dereference (MS15-061)
CVE-2015-1725doswindows_x8622 sep 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Pool Buffer Overflow Drawing Caption Bar (MS15-061)
CVE-2015-1727doswindows_x8622 sep 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
CVE-2015-2507doswindows_x8622 sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!vSolidFillRect' Buffer Overflow (MS15-061)
CVE-2015-1725doswindows_x8622 sep 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - WindowStation Use-After-Free (MS15-061)
CVE-2015-1723doswindows_x8622 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (2)
CVE-2015-1722doswindows_x8622 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DB
SAP NetWeaver < 7.01 - XML External Entity Injection
CVE-2015-7241webappsxml22 sep 2015
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Local Privilege Escalation
CVE-2015-6305localwindows22 sep 2015
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'UserCommitDesktopMemory' Use-After-Free (MS15-073)
CVE-2015-2365doswindows_x8622 sep 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'DeferWindowPos' Use-After-Free (MS15-073)
CVE-2015-2366doswindows_x8622 sep 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (1)
CVE-2015-1722doswindows_x8622 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtGdiStretchBlt' Pool Buffer Overflow (MS15-097)
CVE-2015-2512doswindows_x8622 sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit)
CVE-2015-7768remotewindows21 sep 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.0 - Remote Command Execution
CVE-2015-7767remotewindows20 sep 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-7766remotejava17 sep 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir
anteriorpágina 1036 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.