Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Adobe Flash MovieClip.startDrag - Use-After-Free
CVE-2015-841118 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.setFormat - Use-After-Free
CVE-2015-842218 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.htmlText Setter - Use-After-Free
CVE-2015-842818 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.thickness Setter - Use-After-Free
CVE-2015-842118 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.replaceText - Use-After-Free
CVE-2015-842418 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Microsoft Windows 8.1 - 'win32k' Local Privilege Escalation (MS15-010)
CVE-2015-005718 dic 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
28RIESGO
abrir
Exploit-DB
Adobe Flash TextField.replaceSel - Use-After-Free
CVE-2015-842318 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.type Setter - Use-After-Free
CVE-2015-842918 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash - TextField.Variable Setter Use-After-Free
CVE-2015-842718 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.tabIndex Setter - Use-After-Free
CVE-2015-843118 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.sharpness Setter - Use-After-Free
CVE-2015-842018 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.text Setter - Use-After-Free
CVE-2015-843018 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
Joomla! 1.5 < 3.4.6 - Object Injection 'x-forwarded-for' Header Remote Code Execution
CVE-2015-856218 dic 2015
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
Exploit-DB
Google Chrome - Renderer Process to Browser Process Privilege Escalation
CVE-2015-866418 dic 2015
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 4
23RIESGO
abrir
Exploit-DB
Joomla! 1.5 < 3.4.6 - Object Injection 'x-forwarded-for' Header Remote Code Execution
CVE-2015-856618 dic 2015
The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspeci
23RIESGO
abrir
Exploit-DB
win32k Desktop and Clipboard - Null Pointer Dereference
CVE-2015-617417 dic 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DB
win32k Clipboard Bitmap - Use-After-Free
CVE-2015-617317 dic 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k!OffsetChildren' Null Pointer Dereference
CVE-2015-617117 dic 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DB
Zen Cart 1.5.4 - Local File Inclusion
CVE-2015-835217 dic 2015
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files
28RIESGO
abrir
Exploit-DB
Adobe Flash GradientFill - Use-After-Frees
CVE-2015-804317 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir
Exploit-DB
QEMU (Gentoo) - Local Privilege Escalation
CVE-2015-855617 dic 2015
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
28RIESGO
abrir
Exploit-DB
Adobe Flash TextField.gridFitType Setter - Use-After-Free
CVE-2015-765217 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir
Exploit-DB
Adobe Flash MovieClip.lineStyle - Use-After-Frees
CVE-2015-804417 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
35RIESGO
abrir
Exploit-DB
Adobe Flash TextField.antiAliasType Setter - Use-After-Free
CVE-2015-804617 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir
Exploit-DB
Wireshark - dissect_nbap_MACdPDU_Size SIGSEGV
CVE-2015-873016 dic 2015
epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not va
23RIESGO
abrir
Exploit-DB
Wireshark - addresses_equal 'dissect_rsvp_common' Use-After-Free
CVE-2015-872716 dic 2015
The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.
23RIESGO
abrir
Exploit-DB
Wireshark - find_signature Stack Out-of-Bounds Read
CVE-2015-872616 dic 2015
wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate cer
23RIESGO
abrir
Exploit-DB
Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Buffer Overflow
CVE-2015-874016 dic 2015
The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x befo
23RIESGO
abrir
Exploit-DB
Wireshark - AirPDcapPacketProcess Stack Buffer Overflow
CVE-2015-872316 dic 2015
The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 an
23RIESGO
abrir
Exploit-DB
Wireshark - wmem_alloc Assertion Failure
CVE-2015-873916 dic 2015
The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 imp
23RIESGO
abrir
anteriorpágina 171 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.