Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
Openfire 3.10.2 - Cross-Site Request Forgery
CVE-2015-6973webappsjsp15 sep 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtUserGetClipboardAccessToken Token Leak (MS15-023)
CVE-2015-2527localwindows15 sep 2015
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask TileUserBroker Privilege Escalation
CVE-2015-2528localwindows15 sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Exploit-DB
Openfire 3.10.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2015-6972webappsjsp15 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - MCL (MS15-100) (Metasploit)
CVE-2015-2509remotewindows15 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
Exploit-DB
Openfire 3.10.2 - Privilege Escalation
CVE-2015-7707webappsjsp15 sep 2015
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine EventLog Analyzer < 10.6 build 10060 - SQL Execution
CVE-2015-7387webappsmultiple14 sep 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Exploit-DB
OpenLDAP 2.4.42 - ber_get_next Denial of Service
CVE-2015-6908doslinux11 sep 2015
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a de
28RIESGO
abrir
Exploit-DB
Microsoft Windows Media Center - Command Execution (MS15-100)
CVE-2015-2509remotewindows11 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - Arbitrary mkdir / unlink and chown to Admin Group
CVE-2015-5784localosx10 sep 2015
runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly dro
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Install.framework suid Helper Privilege Escalation
CVE-2015-3704localosx10 sep 2015
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - SUID Root Runner Binary Privilege Escalation
CVE-2015-5754localosx10 sep 2015
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RIESGO
abrir
Exploit-DB
Synology Video Station 1.5-0757 - Multiple Vulnerabilities
CVE-2015-6911webappscgi10 sep 2015
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DB
Synology Video Station 1.5-0757 - Multiple Vulnerabilities
CVE-2015-6912webappscgi10 sep 2015
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharact
28RIESGO
abrir
Exploit-DB
Auto-Exchanger 5.1.0 - Cross-Site Request Forgery
CVE-2015-6827webappsphp09 sep 2015
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentica
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP Session Deserializer - Use-After-Free
CVE-2015-6835dosphp09 sep 2015
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplObjectStorage 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir
Exploit-DB
Qlikview 11.20 SR11 - Blind XML External Entity Injection
CVE-2015-3623webappsxml09 sep 2015
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'Stagefright' Remote Code Execution
CVE-2015-1538remoteandroid09 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
Exploit-DB
Advantech Webaccess 8.0 / 3.4.3 - ActiveX Multiple Vulnerabilities
CVE-2014-9208doswindows08 sep 2015
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attacker
23RIESGO
abrir
Exploit-DB
JSPMySQL Administrador - Multiple Vulnerabilities
CVE-2015-6945webappsjsp07 sep 2015
Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DB
JSPMySQL Administrador - Multiple Vulnerabilities
CVE-2015-6944webappsjsp07 sep 2015
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the a
23RIESGO
abrir
Exploit-DBVexDay Proof
Endian Firewall - Password Change Command Injection (Metasploit)
CVE-2015-5082remotelinux07 sep 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Exploit-DB
WordPress Plugin Contact Form Generator 2.0.1 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2015-6965webappsphp06 sep 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RIESGO
abrir
Exploit-DBVexDay Proof
Tenda N3 Wireless N150 Router - Authentication Bypass
CVE-2015-5995webappshardware03 sep 2015
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RIESGO
abrir
Exploit-DB
Cerb 7.0.3 - Cross-Site Request Forgery
CVE-2015-6545webappsphp02 sep 2015
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the a
23RIESGO
abrir
Exploit-DB
XGI Windows VGA Display Manager 6.14.10.1090 - Arbitrary Write (PoC)
CVE-2015-5466doswindows01 sep 2015
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.10
23RIESGO
abrir
Exploit-DBVexDay Proof
Bedita 3.5.1 - Cross-Site Scripting
CVE-2015-6809webappsphp01 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DB
SiS Windows VGA Display Manager 6.14.10.3930 - Write-What-Where (PoC)
CVE-2015-5465doswindows01 sep 2015
Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allow
23RIESGO
abrir
anteriorpágina 184 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.