Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
80.557 exploits
Exploit-DB
Google Chrome 43.0 - Certificate MIME Handling Integer Overflow
CVE-2015-1265dosmultiple13 ago 2015
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Metasploit300
Android Stagefright MP4 tx3g Integer Overflow
CVE-2015-386413 ago 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Exploit-DB
Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection
CVE-2015-5161webappsmultiple13 ago 2015
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2003 SP2 - TCP/IP IOCTL Privilege Escalation (MS14-070)
CVE-2014-4076localwindows12 ago 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer - CTreeNode::GetCascadedLang Use-After-Free (MS15-079)
CVE-2015-2444doswindows12 ago 2015
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
GitHub PoC1
Exploit for CVE-2015-4495 / mfsa2015-78
CVE-2015-4495HIGHbajo ataque10 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-4495HIGHbajo ataque10 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-547709 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC1
PoC for BIND9 TKEY assert DoS (CVE-2015-5477)
CVE-2015-547709 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Metasploit300
Path Traversal in Oracle GlassFish Server Open Source Edition
CVE-2017-100002808 ago 2015
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
Metasploit300
PCMAN FTP Server Buffer Overflow - PUT Command
CVE-2013-473007 ago 2015
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Exploit-DB
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
CVE-2013-5065HIGHbajo ataquelocalwindows_x8607 ago 2015
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir
Exploit-DB
Dell Netvault Backup 10.0.1.24 - Denial of Service
CVE-2015-5696doswindows07 ago 2015
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting
CVE-2015-2321webappsphp07 ago 2015
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RIESGO
abrir
Exploit-DB
ISC BIND 9 - TKEY Remote Denial of Service (PoC)
CVE-2015-5477dosmultiple05 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Exploit-DB
Linux Kernel - 'espfix64' Nested NMIs Interrupting Privilege Escalation
CVE-2015-3290locallinux_x86-6405 ago 2015
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during n
23RIESGO
abrir
GitHub PoC1
Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software
CVE-2015-547704 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC14
PoC exploit code for CVE-2015-5477 BIND9 TKEY remote DoS vulnerability
CVE-2015-547701 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
CVE-2015-462401 ago 2015
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
CVE-2015-462401 ago 2015
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Exploit-DBVexDay Proof
ISC BIND 9 - TKEY (PoC)
CVE-2015-5477dosmultiple01 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC64
PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure
CVE-2015-547731 jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
CVE-2015-148931 jul 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
CVE-2015-148631 jul 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
CVE-2015-148731 jul 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir
GitHub PoC3
A little Python tool for exploiting CVE-2015-1560 and CVE-2015-1561. Quick'n'dirty. Real dirty.
CVE-2015-156031 jul 2015
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-547731 jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
GitHub PoC11
jvazquez-r7/CVE-2015-5119
CVE-2015-5119HIGHbajo ataque29 jul 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Metasploit300
Heroes of Might and Magic III .h3m Map file Buffer Overflow
CVE-2025-34124HIGH29 jul 2015
Heroes of Might and Magic III .h3m Map File Buffer Overflow
36RIESGO
abrir
Metasploit300
BIND TKEY Query Denial of Service
CVE-2015-547728 jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
anteriorpágina 1044 / 2686siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.