Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
80.753 exploits
Exploit-DB
Comodo GeekBuddy < 4.18.121 - Local Privilege Escalation
CVE-2014-7872localwindows20 may 2015
Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.0/8.1 (x64) - 'TrackPopupMenu' Local Privilege Escalation (MS14-058)
CVE-2014-4113HIGHbajo ataquelocalwindows_x86-6419 may 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DB
QEMU - Floppy Disk Controller (FDC) (PoC)
CVE-2015-3456dosmultiple18 may 2015
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RIESGO
abrir
Exploit-DB
BulletProof FTP Client 2010 - Local Buffer Overflow (DEP Bypass)
CVE-2008-5753localwindows18 may 2015
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1678localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1676localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1679localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'CNG.SYS' Kernel Security Feature Bypass (MS15-052)
CVE-2015-1674localwindows18 may 2015
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not pr
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1701HIGHbajo ataqueransomwarelocalwindows18 may 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1677localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
Exploit-DB
ElasticSearch < 1.4.5 / < 1.5.2 - Directory Traversal
CVE-2015-3337webappsphp18 may 2015
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, a
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Local Privilege Escalation (MS15-051)
CVE-2015-1680localwindows18 may 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
23RIESGO
abrir
GitHub PoC13
Experiments related to CVE-2015-3456
CVE-2015-345617 may 2015
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RIESGO
abrir
Exploit-DB
Burning Board < 2.3.1 - SQL Injection
CVE-2005-1642webappsphp16 may 2015
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attacker
23RIESGO
abrir
GitHub PoC293
Win32k LPE vulnerability used in APT attack
CVE-2015-1701HIGHbajo ataqueransomware12 may 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Metasploit500
Adobe Flash Player Drawing Fill Shader Memory Corruption
CVE-2015-310512 may 2015
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466
60RIESGO
abrir
Metasploit500
Adobe Flash Player ShaderJob Buffer Overflow
CVE-2015-309012 may 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir
Metasploit300
Windows ClientCopyImage Win32k Exploit
CVE-2015-1701HIGHbajo ataqueransomware12 may 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
VulnCheck XDB
local
CVE-2015-1701HIGHbajo ataqueransomware12 may 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Exploit-DB
D-Link DSL-500B Gen 2 - URL Filter Configuration Panel Persistent Cross-Site Scripting
CVE-2013-5223MEDIUMbajo ataquewebappshardware11 may 2015
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RIESGO
abrir
Exploit-DB
D-Link DSL-500B Gen 2 - Parental Control Configuration Panel Persistent Cross-Site Scripting
CVE-2013-5223MEDIUMbajo ataquewebappshardware11 may 2015
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated use
75RIESGO
abrir
Exploit-DB
SynaMan 3.4 Build 1436 - Multiple Vulnerabilities
CVE-2015-3140webappsphp08 may 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - domainMemory ByteArray Use-After-Free (Metasploit)
CVE-2015-0359remotewindows08 may 2015
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - NetConnection Type Confusion (Metasploit)
CVE-2015-0336remotewindows08 may 2015
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir
Exploit-DBVexDay Proof
Novell ZENworks Configuration Management - Arbitrary File Upload (Metasploit)
CVE-2015-0779remotejava08 may 2015
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RIESGO
abrir
GitHub PoC
A checker (site and tool) for CVE-2014-0160. Software from @FiloSottile for iSC Inc..
CVE-2014-0160HIGHbajo ataque08 may 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin RevSlider 3.0.95 - Arbitrary File Upload / Execution (Metasploit)
CVE-2014-9735remotephp08 may 2015
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RIESGO
abrir
Exploit-DB
SynTail 1.5 Build 566 - Multiple Vulnerabilities
CVE-2015-3140webappsphp08 may 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy
23RIESGO
abrir
Exploit-DB
Syncrify Server 3.6 Build 833 - Multiple Vulnerabilities
CVE-2015-3140webappsphp08 may 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Sy
23RIESGO
abrir
Exploit-DB
Xeams 4.5 Build 5755 - Multiple Vulnerabilities
CVE-2015-3141webappsphp08 may 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies Xeams 4.5 Build 5755 and earlier
23RIESGO
abrir
anteriorpágina 1055 / 2692siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.