Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Adobe Acrobat Reader - AFParseDate JavaScript API Restrictions Bypass
CVE-2015-307328 sep 2015
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir
Exploit-DB
Kaseya Virtual System Administrator (VSA) 7.0 < 9.1 - (Authenticated) Arbitrary File Upload
CVE-2015-658928 sep 2015
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RIESGO
abrir
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2015-600028 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RIESGO
abrir
Exploit-DB
vTiger CRM 6.3.0 - (Authenticated) Remote Code Execution
CVE-2016-171328 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir
Exploit-DB
BMC Track-It! 11.4 - Multiple Vulnerabilities
CVE-2016-659928 sep 2015
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService)
28RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-649328 sep 2015
Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 bu
23RIESGO
abrir
Exploit-DB
Mango Automation 2.6.0 - Multiple Vulnerabilities
CVE-2015-790328 sep 2015
SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote
23RIESGO
abrir
Exploit-DB
X2Engine 4.2 - Cross-Site Request Forgery
CVE-2015-507525 sep 2015
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RIESGO
abrir
Exploit-DB
FortiManager 5.2.2 - Persistent Cross-Site Scripting
CVE-2015-803725 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor
23RIESGO
abrir
Exploit-DB
FortiManager 5.2.2 - Persistent Cross-Site Scripting
CVE-2015-803825 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in the Graphical User Interface (GUI) in Fortinet FortiManager befor
23RIESGO
abrir
Exploit-DB
X2Engine 4.2 - Arbitrary File Upload
CVE-2015-507425 sep 2015
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'NtGdiBitBlt' Buffer Overflow (MS15-097)
CVE-2015-251224 sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
Exploit-DB
SMF (Simple Machine Forum) 2.0.10 - Remote Memory Exfiltration
CVE-2015-414824 sep 2015
The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not
28RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-738223 sep 2015
SQL injection vulnerability in install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers
23RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-738123 sep 2015
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6
23RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-600923 sep 2015
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to e
23RIESGO
abrir
Exploit-DB
refbase 0.9.6 - Multiple Vulnerabilities
CVE-2015-600823 sep 2015
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands
23RIESGO
abrir
Exploit-DB
Cisco AnyConnect 3.1.08009 - Local Privilege Escalation (via DMG Install Script)
CVE-2015-630623 sep 2015
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions,
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (1)
CVE-2015-172222 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DB
SAP NetWeaver < 7.01 - XML External Entity Injection
CVE-2015-724122 sep 2015
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (2)
CVE-2015-172222 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.0 - Directory Traversal
CVE-2015-760322 sep 2015
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
CVE-2015-250722 sep 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'bGetRealizedBrush' Use-After-Free (MS15-097)
CVE-2015-251822 sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Use-After-Free with Cursor Object (MS15-097)
CVE-2015-251722 sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'FlashWindowEx​' Memory Corruption (MS15-097)
CVE-2015-251122 sep 2015
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'HmgAllocateObjectAttr' Use-After-Free (MS15-061)
CVE-2015-172622 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Brush Object Use-After-Free (MS15-061)
CVE-2015-172422 sep 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Pool Buffer Overflow Drawing Caption Bar (MS15-061)
CVE-2015-172722 sep 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RIESGO
abrir
Exploit-DB
h5ai < 0.25.0 - Unrestricted Arbitrary File Upload
CVE-2015-320322 sep 2015
Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir
anteriorpágina 176 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.