Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.553exploits catalogados
37.310CVEs con explotación pública
24.695probados en laboratorio
80.554 exploits
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit)
CVE-2015-7768remotewindows21 sep 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.0 - Remote Command Execution
CVE-2015-7767remotewindows20 sep 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-7766remotejava17 sep 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-2433localwindows_x86-6417 sep 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-2426HIGHbajo ataquelocalwindows_x86-6417 sep 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir
Exploit-DB
VBox Satellite Express 2.3.17.3 - Arbitrary Write
CVE-2015-6923doswindows17 sep 2015
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-7765remotejava17 sep 2015
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - libstagefright Integer Overflow Remote Code Execution
CVE-2015-3864remoteandroid17 sep 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
CVE-2015-2510doswindows16 sep 2015
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel 2007/2010/2013 - BIFFRecord Use-After-Free
CVE-2015-2523doswindows16 sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compati
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
CVE-2015-2521doswindows16 sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RIESGO
abrir
Exploit-DB
FAROL - SQL Injection
CVE-2015-6962webappsphp16 sep 2015
SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
CVE-2015-2520doswindows16 sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask SettingsSyncDiagnostics Privilege Escalation
CVE-2015-2524localwindows15 sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - MCL (MS15-100) (Metasploit)
CVE-2015-2509remotewindows15 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
Exploit-DBVexDay Proof
CMS Bolt - Arbitrary File Upload (Metasploit)
CVE-2015-7309remotephp15 sep 2015
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authent
50RIESGO
abrir
Exploit-DB
Openfire 3.10.2 - Privilege Escalation
CVE-2015-7707webappsjsp15 sep 2015
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtUserGetClipboardAccessToken Token Leak (MS15-023)
CVE-2015-2527localwindows15 sep 2015
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10130) - User Mode Font Driver Thread Permissions Privilege Escalation
CVE-2015-2508localwindows15 sep 2015
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RIESGO
abrir
Exploit-DB
WordPress Plugin CP Reservation Calendar 1.1.6 - SQL Injection
CVE-2015-7235webappsphp15 sep 2015
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask TileUserBroker Privilege Escalation
CVE-2015-2528localwindows15 sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Exploit-DB
Openfire 3.10.2 - Cross-Site Request Forgery
CVE-2015-6973webappsjsp15 sep 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Task Scheduler - 'DeleteExpiredTaskAfter' File Deletion Privilege Escalation
CVE-2015-2525localwindows15 sep 2015
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1
35RIESGO
abrir
Exploit-DB
Openfire 3.10.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2015-6972webappsjsp15 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine EventLog Analyzer < 10.6 build 10060 - SQL Execution
CVE-2015-7387webappsmultiple14 sep 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Metasploit0
ManageEngine OpManager Remote Code Execution
CVE-2015-776614 sep 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir
Metasploit0
ManageEngine OpManager Remote Code Execution
CVE-2015-776514 sep 2015
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-363612 sep 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
Exploit-DB
OpenLDAP 2.4.42 - ber_get_next Denial of Service
CVE-2015-6908doslinux11 sep 2015
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a de
28RIESGO
abrir
Exploit-DB
Microsoft Windows Media Center - Command Execution (MS15-100)
CVE-2015-2509remotewindows11 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
anteriorpágina 1038 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.