Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
24.443 exploits
Exploit-DB
Apport 2.14.1 (Ubuntu 14.04.2) - Local Privilege Escalation
CVE-2015-1318locallinux17 abr 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir
Exploit-DB
Oracle - Outside-In '.DOCX' File Parsing Memory Corruption
CVE-2015-0474doswindows17 abr 2015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.
23RIESGO
abrir
Exploit-DB
Oracle - Outside-In '.DOCX' File Parsing Memory Corruption
CVE-2015-0493doswindows17 abr 2015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.
23RIESGO
abrir
Exploit-DB
Oracle Hyperion Smart View for Office 11.1.2.3.000 - Crash (PoC)
CVE-2015-2572doswindows17 abr 2015
Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and ear
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'HTTP.sys' HTTP Request Parsing Denial of Service (MS15-034)
CVE-2015-1635CRITICALbajo ataquedoswindows16 abr 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DB
Microsoft Windows - 'HTTP.sys' (PoC) (MS15-034)
CVE-2015-1635CRITICALbajo ataquedoswindows15 abr 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DBVexDay Proof
Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation
CVE-2015-1862locallinux14 abr 2015
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot
23RIESGO
abrir
Exploit-DBVexDay Proof
Abrt (Fedora 21) - Race Condition
CVE-2015-1862locallinux14 abr 2015
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot
23RIESGO
abrir
Exploit-DB
Samsung iPOLiS - ReadConfigValue Remote Code Execution
CVE-2015-0555remotewindows14 abr 2015
Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote
23RIESGO
abrir
Exploit-DBVexDay Proof
Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation
CVE-2015-1318locallinux14 abr 2015
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir
Exploit-DBVexDay Proof
Abrt (Fedora 21) - Race Condition
CVE-2015-3315locallinux14 abr 2015
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RIESGO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.5 - File Copy
CVE-2015-3306remotelinux13 abr 2015
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Exploit-DB
Samba < 3.6.2 (x86) - Denial of Service (PoC)
CVE-2015-0240doslinux_x8613 abr 2015
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - 'Rootpipe' Local Privilege Escalation (Metasploit)
CVE-2015-1130HIGHbajo ataquelocalosx13 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir
Exploit-DB
Linux Kernel 3.13/3.14 (Ubuntu) - 'splice()' System Call Local Denial of Service
CVE-2014-7822doslinux13 abr 2015
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restrictio
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - casi32 Integer Overflow (Metasploit)
CVE-2014-0569remotewindows13 abr 2015
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and bef
60RIESGO
abrir
Exploit-DBVexDay Proof
Lenovo System Update - Local Privilege Escalation (Metasploit)
CVE-2015-2219localwindows12 abr 2015
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allo
38RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX < 10.7.5/10.8.2/10.9.5/10.10.2 - 'Rootpipe' Local Privilege Escalation
CVE-2015-1130HIGHbajo ataquelocalosx09 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir
Exploit-DBVexDay Proof
Novell ZENworks Configuration Management 11.3.1 - Remote Code Execution
CVE-2015-0779webappsjsp08 abr 2015
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RIESGO
abrir
Exploit-DBVexDay Proof
SolarWinds Firewall Security Manager 6.6.5 - Client Session Handling (Metasploit)
CVE-2015-2284remotewindows08 abr 2015
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privile
60RIESGO
abrir
Exploit-DB
WordPress Plugin Shareaholic 7.6.0.3 - Cross-Site Scripting
CVE-2014-9311webappsphp08 abr 2015
Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
JBoss Seam 2 - Arbitrary File Upload / Execution (Metasploit)
CVE-2010-1871HIGHbajo ataqueremotejsp06 abr 2015
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly
100RIESGO
abrir
Exploit-DB
WebGate WinRDS 2.0.8 - PlaySiteAllChannel Stack Buffer Overflow
CVE-2015-2094remotewindows02 abr 2015
Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to
28RIESGO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-7196webappsmultiple02 abr 2015
20RIESGO
abrir
Exploit-DBVexDay Proof
WebGate eDVR Manager 2.6.4 - SiteChannel Property Stack Buffer Overflow
CVE-2015-2098remotewindows02 abr 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir
Exploit-DBVexDay Proof
WebGate eDVR Manager 2.6.4 - AudioOnlySiteChannel Stack Buffer Overflow
CVE-2015-2098remotewindows02 abr 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir
Exploit-DB
WordPress Plugin Simple Ads Manager 2.5.94 - Arbitrary File Upload
CVE-2015-2825webappsphp02 abr 2015
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres
28RIESGO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-3671webappsmultiple02 abr 2015
20RIESGO
abrir
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
CVE-2014-3659webappsmultiple02 abr 2015
20RIESGO
abrir
Exploit-DB
WebGate WESP SDK 1.2 - ChangePassword Stack Overflow
CVE-2015-2097remotewindows02 abr 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RIESGO
abrir
anteriorpágina 196 / 815siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.