Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1487remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir
Exploit-DB
WordPress Plugin WP Symposium 15.1 - 'get_album_item.php' SQL Injection
CVE-2015-6522webappsphp18 ago 2015
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RIESGO
abrir
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-8008webappsmultiple18 ago 2015
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manage
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1486remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
CVE-2014-6271CRITICALbajo ataquewebappsmultiple18 ago 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
CVE-2014-6332HIGHbajo ataqueremotewindows17 ago 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2016-3088CRITICALbajo ataqueremotewindows17 ago 2015
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2015-1830remotewindows17 ago 2015
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir
Exploit-DB
Mozilla Firefox < 39.03 - 'pdf.js' Same Origin Policy
CVE-2015-4495HIGHbajo ataquelocalmultiple15 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RIESGO
abrir
Exploit-DB
Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection
CVE-2015-5161webappsmultiple13 ago 2015
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
Exploit-DB
Google Chrome 43.0 - Certificate MIME Handling Integer Overflow
CVE-2015-1265dosmultiple13 ago 2015
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DB
Microsoft Windows 8.1 - DCOM DCE/RPC Local NTLM Reflection Privilege Escalation (MS15-076)
CVE-2015-2370localwindows13 ago 2015
The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer - CTreeNode::GetCascadedLang Use-After-Free (MS15-079)
CVE-2015-2444doswindows12 ago 2015
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2003 SP2 - TCP/IP IOCTL Privilege Escalation (MS14-070)
CVE-2014-4076localwindows12 ago 2015
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Exploit-DB
Dell Netvault Backup 10.0.1.24 - Denial of Service
CVE-2015-5696doswindows07 ago 2015
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting
CVE-2015-2321webappsphp07 ago 2015
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RIESGO
abrir
Exploit-DB
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
CVE-2013-5065HIGHbajo ataquelocalwindows_x8607 ago 2015
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir
Exploit-DB
ISC BIND 9 - TKEY Remote Denial of Service (PoC)
CVE-2015-5477dosmultiple05 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Exploit-DB
Linux Kernel - 'espfix64' Nested NMIs Interrupting Privilege Escalation
CVE-2015-3290locallinux_x86-6405 ago 2015
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during n
23RIESGO
abrir
Exploit-DBVexDay Proof
ISC BIND 9 - TKEY (PoC)
CVE-2015-5477dosmultiple01 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Exploit-DBVexDay Proof
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation
CVE-2015-5602locallinux28 jul 2015
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3246doslinux27 jul 2015
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4665webappsphp27 jul 2015
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RIESGO
abrir
Exploit-DB
WordPress Plugin Count Per Day 3.4 - SQL Injection
CVE-2015-5533webappsphp27 jul 2015
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4666webappsphp27 jul 2015
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attack
43RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4668webappsphp27 jul 2015
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4664webappsphp27 jul 2015
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers t
28RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4667webappsphp27 jul 2015
Multiple hardcoded credentials in Xsuite 2.x.
28RIESGO
abrir
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3245doslinux27 jul 2015
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Exploit-DB
Xceedium Xsuite - Multiple Vulnerabilities
CVE-2015-4669webappsphp27 jul 2015
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the sy
23RIESGO
abrir
anteriorpágina 188 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.