Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
80.646 exploits
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3111doswindows23 jun 2015
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RIESGO
abrir
Exploit-DBVexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
CVE-2015-3112doswindows23 jun 2015
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RIESGO
abrir
Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVE-2015-3043HIGHbajo ataque23 jun 2015
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir
Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVE-2015-3113HIGHbajo ataque23 jun 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir
Exploit-DBVexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
CVE-2015-1158remotemultiple22 jun 2015
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir
Exploit-DBVexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
CVE-2007-3071webappswindows19 jun 2015
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RIESGO
abrir
Exploit-DBVexDay Proof
Lively Cart - SQL Injection
CVE-2015-5148webappsmultiple19 jun 2015
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RIESGO
abrir
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5150webappsmultiple19 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RIESGO
abrir
Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
CVE-2015-5149webappsmultiple19 jun 2015
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RIESGO
abrir
GitHub PoC1
This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque17 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
CVE-2015-5079webappsphp17 jun 2015
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails 4.0.x/4.1.x/4.2.x (Web Console v2) - Whitelist Bypass Code Execution (Metasploit)
CVE-2015-3224remotemultiple16 jun 2015
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
Exploit-DB
Ektron CMS 9.10 SP1 (Build 9.1.0.184.1.114) - Cross-Site Request Forgery
CVE-2015-3624webappsphp16 jun 2015
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
CVE-2015-1328locallinux16 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Exploit-DB
TYPO3 Extension Akronymmanager 0.5.0 - SQL Injection
CVE-2015-2803webappsphp16 jun 2015
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
CVE-2015-1328locallinux16 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Metasploit400
Overlayfs Privilege Escalation
CVE-2015-866016 jun 2015
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
Metasploit400
Overlayfs Privilege Escalation
CVE-2015-132816 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Metasploit600
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution
CVE-2015-322416 jun 2015
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
Exploit-DBVexDay Proof
Milw0rm Clone Script 1.0 - '/admin/login.php' Authentication Bypass
CVE-2015-4658webappsphp15 jun 2015
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute
23RIESGO
abrir
Exploit-DB
WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload
CVE-2015-4455webappsphp12 jun 2015
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin
50RIESGO
abrir
Exploit-DBVexDay Proof
ZCMS 1.1 - Multiple Vulnerabilities
CVE-2015-7347webappsjsp12 jun 2015
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
23RIESGO
abrir
Exploit-DB
ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
CVE-2015-4659webappsphp12 jun 2015
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the auth
23RIESGO
abrir
Metasploit300
D-Link Cookie Command Execution
CVE-2025-34125CRITICAL12 jun 2015
D-Link DSP-W110A1 Cookie Command Injection
63RIESGO
abrir
Exploit-DB
Opsview 4.6.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2015-4420webappsmultiple12 jun 2015
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SE HTML5 Album Audio Player 1.1.0 - Directory Traversal
CVE-2015-4414webappsphp12 jun 2015
Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)
43RIESGO
abrir
Exploit-DBVexDay Proof
ZCMS 1.1 - Multiple Vulnerabilities
CVE-2015-7346webappsjsp12 jun 2015
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir
Exploit-DB
OSSEC 2.7 < 2.8.1 - 'diff' Local Privilege Escalation
CVE-2015-3222locallinux11 jun 2015
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
23RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2996webappshardware10 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
CVE-2015-2998webappshardware10 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
anteriorpágina 1050 / 2689siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.