Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.dll' CFF table (ATMFD+0x3440b / ATMFD+0x3440e) Invalid Memory Access
CVE-2015-2460doswindows21 ago 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Exploit-DB
Netsweeper 2.6.29.8 - SQL Injection
CVE-2014-9613webappsphp21 ago 2015
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' Write to Uninitialized Address Due to Malformed CFF Table
CVE-2015-2432doswindows21 ago 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing IUP[] Program Instruction Pool-Based Buffer Overflow
CVE-2015-2455doswindows21 ago 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RIESGO
abrir
Exploit-DB
Netsweeper 4.0.8 - Arbitrary File Upload / Execution
CVE-2014-9619webappsphp21 ago 2015
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.
23RIESGO
abrir
Exploit-DB
Netsweeper 4.0.8 - SQL Injection / Authentication Bypass
CVE-2014-9605webappsphp21 ago 2015
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
23RIESGO
abrir
Exploit-DB
Netsweeper 4.0.8 - Authentication Bypass (via New Profile Creation)
CVE-2014-9618webappsphp21 ago 2015
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
CVE-2015-2470doswindows21 ago 2015
Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 201
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_BLTHoriz Out-of-Bounds Pool Write
CVE-2015-2464doswindows21 ago 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed Name INDEX in the CFF Table
CVE-2015-2461doswindows21 ago 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' CFF table (ATMFD+0x34072 / ATMFD+0x3407b) Invalid Memory Access
CVE-2015-2459doswindows21 ago 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!fsc_RemoveDups Out-of-Bounds Pool Memory Access
CVE-2015-2463doswindows21 ago 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'mso.dll' Use-After-Free (MS15-081)
CVE-2015-2467doswindows21 ago 2015
Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Offic
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Font Processing win32k!scl_ApplyTranslation Pool-Based Buffer Overflow
CVE-2015-2456doswindows21 ago 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.dll' CharString Stream Out-of-Bounds Reads (MS15-021)
CVE-2015-2458doswindows21 ago 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'wwlib.dll' Type Confusion (MS15-081)
CVE-2015-2469doswindows21 ago 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, and Office for Mac 2011 allow remote attackers to execute arbit
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'mso.dll' Arbitrary Free (MS15-081)
CVE-2015-2468doswindows21 ago 2015
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office fo
28RIESGO
abrir
Exploit-DB
Netsweeper 3.0.6 - Authentication Bypass
CVE-2014-9611webappsphp21 ago 2015
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ATMFD.DLL' Out-of-Bounds Read Due to Malformed FDSelect Offset in the CFF Table
CVE-2015-2462doswindows21 ago 2015
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
35RIESGO
abrir
Exploit-DB
Netsweeper 4.0.8 - Authentication Bypass (via Disabling of IP Quarantine)
CVE-2014-9610webappsphp21 ago 2015
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication an
23RIESGO
abrir
Exploit-DB
Netsweeper 4.0.4 - SQL Injection
CVE-2014-9612webappsphp21 ago 2015
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-363621 ago 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla - Maintenance Service Log File Overwrite Privilege Escalation
CVE-2015-4481localwindows21 ago 2015
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.0 - Remote Denial of Service (PoC)
CVE-2015-7767doswindows21 ago 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RIESGO
abrir
Exploit-DB
WordPress Plugin MDC Private Message 1.0.0 - Persistent Cross-Site Scripting
CVE-2015-6805webappsphp21 ago 2015
Cross-site scripting (XSS) vulnerability in the MDC Private Message plugin 1.0.0 for WordPress allows remote authenticat
23RIESGO
abrir
GitHub PoC
Windows 2k3 tcpip.sys Privilege Escalation
CVE-2014-407620 ago 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Metasploit600
ManageEngine ServiceDesk Plus Arbitrary File Upload
CVE-2019-8394HIGHbajo ataque20 ago 2015
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via l
98RIESGO
abrir
Exploit-DB
Aruba Mobility Controller 6.4.2.8 - Multiple Vulnerabilities
CVE-2015-5437webappsxml20 ago 2015
20RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - '.SWF' Out-of-Bounds Memory Read (2)
CVE-2015-5132doswindows19 ago 2015
Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RIESGO
abrir
GitHub PoC1
PoC exploit for CVE-2015-5477 in php
CVE-2015-547719 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
anteriorpágina 1041 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.