Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
VulnCheck XDB
denial-of-service
CVE-2015-363612 sep 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
Exploit-DB
OpenLDAP 2.4.42 - ber_get_next Denial of Service
CVE-2015-6908doslinux11 sep 2015
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a de
28RIESGO
abrir
Exploit-DB
Microsoft Windows Media Center - Command Execution (MS15-100)
CVE-2015-2509remotewindows11 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
GitHub PoC1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153810 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
Exploit-DB
Synology Video Station 1.5-0757 - Multiple Vulnerabilities
CVE-2015-6912webappscgi10 sep 2015
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharact
28RIESGO
abrir
Exploit-DB
Synology Video Station 1.5-0757 - Multiple Vulnerabilities
CVE-2015-6911webappscgi10 sep 2015
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-5119HIGHbajo ataque10 sep 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - SUID Root Runner Binary Privilege Escalation
CVE-2015-5754localosx10 sep 2015
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - Arbitrary mkdir / unlink and chown to Admin Group
CVE-2015-5784localosx10 sep 2015
runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly dro
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Install.framework suid Helper Privilege Escalation
CVE-2015-3704localosx10 sep 2015
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RIESGO
abrir
GitHub PoC205
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153810 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
CVE-2015-5119HIGHbajo ataque10 sep 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Exploit-DB
Qlikview 11.20 SR11 - Blind XML External Entity Injection
CVE-2015-3623webappsxml09 sep 2015
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplObjectStorage 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir
GitHub PoC3
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
CVE-2015-153809 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
Exploit-DBVexDay Proof
PHP Session Deserializer - Use-After-Free
CVE-2015-6835dosphp09 sep 2015
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir
Exploit-DB
Auto-Exchanger 5.1.0 - Cross-Site Request Forgery
CVE-2015-6827webappsphp09 sep 2015
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentica
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'Stagefright' Remote Code Execution
CVE-2015-1538remoteandroid09 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC1
drone789/CVE-2012-1823
CVE-2012-1823CRITICALbajo ataque08 sep 2015
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
Metasploit600
MS15-100 Microsoft Windows Media Center MCL Vulnerability
CVE-2015-250908 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2012-1823CRITICALbajo ataque08 sep 2015
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
Exploit-DB
Advantech Webaccess 8.0 / 3.4.3 - ActiveX Multiple Vulnerabilities
CVE-2014-9208doswindows08 sep 2015
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attacker
23RIESGO
abrir
Exploit-DB
JSPMySQL Administrador - Multiple Vulnerabilities
CVE-2015-6944webappsjsp07 sep 2015
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the a
23RIESGO
abrir
Exploit-DB
JSPMySQL Administrador - Multiple Vulnerabilities
CVE-2015-6945webappsjsp07 sep 2015
Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Endian Firewall - Password Change Command Injection (Metasploit)
CVE-2015-5082remotelinux07 sep 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Exploit-DB
WordPress Plugin Contact Form Generator 2.0.1 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2015-6965webappsphp06 sep 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RIESGO
abrir
GitHub PoC1
Just an attempt to adapt for Note 4, I do not know what I am doing.
CVE-2014-432204 sep 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
Metasploit600
F5 iControl iCall::Script Root Command Execution
CVE-2015-362803 sep 2015
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
Exploit-DBVexDay Proof
Tenda N3 Wireless N150 Router - Authentication Bypass
CVE-2015-5995webappshardware03 sep 2015
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RIESGO
abrir
anteriorpágina 1039 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.