Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Metasploit300
MS15-018 Microsoft Internet Explorer 10 and 11 Cross-Domain JavaScript Injection
CVE-2015-007201 feb 2015
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass t
60RIESGO
abrir
Exploit-DB
Symantec Altiris Agent 6.9 (Build 648) - Local Privilege Escalation
CVE-2014-7286localwindows01 feb 2015
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local us
23RIESGO
abrir
Exploit-DB
Trend Micro 8.0.1133 (Multiple Products) - Local Privilege Escalation
CVE-2014-9641localwindows31 ene 2015
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RIESGO
abrir
GitHub PoC
glibc gethostbyname bug
CVE-2015-023530 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
McAfee Data Loss Prevention Endpoint - Arbitrary Write Privilege Escalation
CVE-2015-1305localwindows30 ene 2015
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, an
23RIESGO
abrir
Metasploit300
X360 VideoPlayer ActiveX Control Buffer Overflow
CVE-2025-34128HIGH30 ene 2015
X360 VideoPlayer ActiveX Control Buffer Overflow via ConvertFile()
36RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector 8.x - Remote Command Execution
CVE-2014-2623remotehp-ux30 ene 2015
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
CVE-2014-7288remotewindows30 ene 2015
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Multiple Vulnerabilities
CVE-2014-8612dosfreebsd29 ene 2015
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Multiple Vulnerabilities
CVE-2014-0998dosfreebsd29 ene 2015
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows
23RIESGO
abrir
Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
CVE-2012-4891webappshardware29 ene 2015
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RIESGO
abrir
Exploit-DB
Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
CVE-2015-0235doslinux29 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2003 SP2 - Local Privilege Escalation (MS14-070)
CVE-2014-4076localwindows29 ene 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Exploit-DB
Apple Mac OSX < 10.10.x - GateKeeper Bypass
CVE-2014-8826localosx29 ene 2015
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RIESGO
abrir
GitHub PoC
cookbook for update glibc. CVE-2015-0235(GHOST)
CVE-2015-023529 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC
Playbooks 'Fix for CVE-2015-0235(GHOST)' running on Ansible
CVE-2015-023529 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
CVE-2012-4889webappshardware29 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RIESGO
abrir
GitHub PoC1
gethostbyname*() buffer overflow exploit in glibc - CVE-2015-0235 https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vulnerability
CVE-2015-023529 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Metasploit300
ManageEngine Multiple Products Arbitrary Directory Listing
CVE-2014-786328 ene 2015
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir
Metasploit300
ManageEngine Multiple Products Arbitrary File Download
CVE-2014-786328 ene 2015
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir
Metasploit600
Oracle Weblogic Server Deserialization RCE - Raw Object
CVE-2015-4852CRITICALbajo ataque28 ene 2015
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
GitHub PoC1
Ansible playbook, to check for CVE-2015-0235 (GHOST) vulnerability
CVE-2015-023528 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC1
furyutei/CVE-2015-0235_GHOST
CVE-2015-023528 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC
CVE-2015-0235 patches lenny libc6 packages for amd64
CVE-2015-023528 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC3
A chef cookbook to test the GHOST vulnerability
CVE-2015-023527 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC6
Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security
CVE-2015-023527 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
GitHub PoC15
Ansible playbook to check vulnerability for CVE-2015-0235
CVE-2015-023527 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Metasploit500
Exim GHOST (glibc gethostbyname) Buffer Overflow
CVE-2015-023527 ene 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
Symantec Data Center Security - Multiple Vulnerabilities
CVE-2014-9226webappsmultiple26 ene 2015
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security:
23RIESGO
abrir
Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
CVE-2015-1478webappsmultiple26 ene 2015
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attac
23RIESGO
abrir
anteriorpágina 1068 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.