Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Google Android - libstagefright Integer Overflow Remote Code Execution
CVE-2015-3864remoteandroid17 sep 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-7766remotejava17 sep 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
CVE-2015-2521doswindows16 sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel 2007/2010/2013 - BIFFRecord Use-After-Free
CVE-2015-2523doswindows16 sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compati
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
CVE-2015-2520doswindows16 sep 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
CVE-2015-2510doswindows16 sep 2015
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Task Scheduler - 'DeleteExpiredTaskAfter' File Deletion Privilege Escalation
CVE-2015-2525localwindows15 sep 2015
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtUserGetClipboardAccessToken Token Leak (MS15-023)
CVE-2015-2527localwindows15 sep 2015
The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10130) - User Mode Font Driver Thread Permissions Privilege Escalation
CVE-2015-2508localwindows15 sep 2015
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RIESGO
abrir
Exploit-DBVexDay Proof
CMS Bolt - Arbitrary File Upload (Metasploit)
CVE-2015-7309remotephp15 sep 2015
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authent
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - MCL (MS15-100) (Metasploit)
CVE-2015-2509remotewindows15 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask TileUserBroker Privilege Escalation
CVE-2015-2528localwindows15 sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CreateObjectTask SettingsSyncDiagnostics Privilege Escalation
CVE-2015-2524localwindows15 sep 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Exploit-DBVexDay Proof
ManageEngine EventLog Analyzer < 10.6 build 10060 - SQL Execution
CVE-2015-7387webappsmultiple14 sep 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - SUID Root Runner Binary Privilege Escalation
CVE-2015-5754localosx10 sep 2015
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Install.framework suid Helper Privilege Escalation
CVE-2015-3704localosx10 sep 2015
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Install.Framework - Arbitrary mkdir / unlink and chown to Admin Group
CVE-2015-5784localosx10 sep 2015
runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly dro
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'Stagefright' Remote Code Execution
CVE-2015-1538remoteandroid09 sep 2015
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplObjectStorage 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-Free
CVE-2015-6834dosphp09 sep 2015
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir
Exploit-DBVexDay Proof
PHP Session Deserializer - Use-After-Free
CVE-2015-6835dosphp09 sep 2015
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir
Exploit-DBVexDay Proof
Endian Firewall - Password Change Command Injection (Metasploit)
CVE-2015-5082remotelinux07 sep 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Exploit-DBVexDay Proof
Tenda N3 Wireless N150 Router - Authentication Bypass
CVE-2015-5995webappshardware03 sep 2015
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RIESGO
abrir
Exploit-DBVexDay Proof
Bedita 3.5.1 - Cross-Site Scripting
CVE-2015-6809webappsphp01 sep 2015
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)
CVE-2015-3673localosx31 ago 2015
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RIESGO
abrir
Exploit-DBVexDay Proof
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
CVE-2015-7243localwindows31 ago 2015
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir
Exploit-DBVexDay Proof
PCMan FTP Server 2.0.7 - 'RENAME' Remote Buffer Overflow
CVE-2013-4730remotewindows29 ago 2015
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle GlassFish Server 4.1 - Directory Traversal
CVE-2017-1000028webappsmultiple27 ago 2015
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
Exploit-DBVexDay Proof
QEMU - Programmable Interrupt Timer Controller Heap Overflow
CVE-2015-3214dosmultiple27 ago 2015
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection
CVE-2016-6195webappsphp25 ago 2015
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 bef
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.