Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Exploit-DBVexDay Proof
Adobe Flash AS2 - textfield.filters Use-After-Free (2)
CVE-2015-3118doswindows19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - URL Resource Use-After-Free
CVE-2015-4430doswindows19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow in ID3 Tag Parsing
CVE-2015-5560dosmultiple19 ago 2015
Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Setting Value Use-After-Free
CVE-2015-5539dosmultiple19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - XMLSocket Destructor Not Cleared Before Setting User Data in connect
CVE-2015-5554doslinux_x86-6419 ago 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash AS2 - DisplacementMapFilter.mapBitmap Use-After-Free (1)
CVE-2015-3080doswindows19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Heap Buffer Overflow Loading '.FLV' File with Nellymoser Audio Codec
CVE-2015-4432doslinux_x86-6419 ago 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows an
35RIESGO
abrir
Metasploit600
Apache ActiveMQ 5.x-5.11.1 Directory Traversal Shell Upload
CVE-2015-183019 ago 2015
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - swapDepths Use-After-Free
CVE-2015-5550dosmultiple19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Heap Use-After-Free in SurfaceFilterList::C​reateFromScriptAtom
CVE-2015-5563doswindows19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - textfield.gridFitType Use-After-Free
CVE-2015-5557dosmultiple19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Pointer Crash in Button Handling
CVE-2015-5547doslinux19 ago 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Heap Buffer Overflow Due to Indexing Error When Loading FLV File
CVE-2015-5118doslinux_x86-6419 ago 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows an
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in UTF Conversion
CVE-2015-3134doswindows19 ago 2015
Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - AVSS.setSubscribedTags Use-After-Free Memory Corruption
CVE-2015-3088doswindows19 ago 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows an
35RIESGO
abrir
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-8008webappsmultiple18 ago 2015
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manage
23RIESGO
abrir
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-6271CRITICALbajo ataquewebappsmultiple18 ago 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1487remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1489remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1486remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir
Metasploit300
WordPress Symposium Plugin SQL Injection
CVE-2015-652218 ago 2015
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RIESGO
abrir
GitHub PoC3
PoC - Binary patches for CVE-2015-3864 (NOT for production, use at your own risk)
CVE-2015-386418 ago 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Exploit-DB
WordPress Plugin WP Symposium 15.1 - 'get_album_item.php' SQL Injection
CVE-2015-6522webappsphp18 ago 2015
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RIESGO
abrir
Metasploit600
CMS Bolt File Upload Vulnerability
CVE-2015-730917 ago 2015
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authent
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2015-1830remotewindows17 ago 2015
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
CVE-2014-6332HIGHbajo ataqueremotewindows17 ago 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2016-3088CRITICALbajo ataqueremotewindows17 ago 2015
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
GitHub PoC24
CVE-2014-4322 Exploit
CVE-2014-432216 ago 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
Exploit-DB
Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
CVE-2015-4495HIGHbajo ataquelocalmultiple15 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir
Exploit-DB
Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection
CVE-2015-5161webappsmultiple13 ago 2015
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
anteriorpágina 1043 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.