Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Adobe Flash - swapDepths Use-After-Free
CVE-2015-5550dosmultiple19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - XMLSocket Destructor Not Cleared Before Setting User Data in connect
CVE-2015-5554doslinux_x86-6419 ago 2015
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - textfield.gridFitType Use-After-Free
CVE-2015-5557dosmultiple19 ago 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow in ID3 Tag Parsing
CVE-2015-5560dosmultiple19 ago 2015
Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RIESGO
abrir
Exploit-DBVexDay Proof
Flash Player - Integer Overflow in Function.apply
CVE-2015-3087doswindows19 ago 2015
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and
45RIESGO
abrir
Exploit-DBVexDay Proof
Flash - Issues in DefineBitsLossless and DefineBitsLossless2 Leads to Using Uninitialized Memory
CVE-2015-3093doswindows19 ago 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1487remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1486remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
CVE-2015-1489remotewindows_x8618 ago 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
CVE-2014-6332HIGHbajo ataqueremotewindows17 ago 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2016-3088CRITICALbajo ataqueremotewindows17 ago 2015
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
CVE-2015-1830remotewindows17 ago 2015
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir
Exploit-DBVexDay Proof
ISC BIND 9 - TKEY (PoC)
CVE-2015-5477dosmultiple01 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Exploit-DBVexDay Proof
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation
CVE-2015-5602locallinux28 jul 2015
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3245doslinux27 jul 2015
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Exploit-DBVexDay Proof
Libuser Library - Multiple Vulnerabilities
CVE-2015-3246doslinux27 jul 2015
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RIESGO
abrir
Exploit-DBVexDay Proof
SysAid Help Desk 'rdslogs' - Arbitrary File Upload (Metasploit)
CVE-2015-2995remotejava21 jul 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download
CVE-2015-5471webappsphp13 jul 2015
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Accellion FTA - getStatus verify_oauth_token Command Execution (Metasploit)
CVE-2015-2857remotehardware13 jul 2015
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - opaqueBackground Use-After-Free (Metasploit)
CVE-2015-5122HIGHbajo ataqueremotewindows13 jul 2015
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir
Exploit-DBVexDay Proof
Western Digital Arkeia < 11.0.12 - Remote Code Execution (Metasploit)
CVE-2015-7709remotemultiple13 jul 2015
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
CVE-2015-5119HIGHbajo ataqueremotemultiple08 jul 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
CVE-2015-3113HIGHbajo ataqueremotemultiple08 jul 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP E-Commerce Shop Styling 2.5 - Arbitrary File Download
CVE-2015-5468webappsphp08 jul 2015
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack
28RIESGO
abrir
Exploit-DBVexDay Proof
AirLink101 SkyIPCam1620W - OS Command Injection
CVE-2015-2280webappshardware08 jul 2015
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709
28RIESGO
abrir
Exploit-DBVexDay Proof
AirLive (Multiple Products) - OS Command Injection
CVE-2015-2279webappshardware08 jul 2015
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
CVE-2015-3043HIGHbajo ataqueremotemultiple08 jul 2015
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - Drawing Fill Shader Memory Corruption (Metasploit)
CVE-2015-3105remotemultiple30 jun 2015
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466
60RIESGO
abrir
Exploit-DBVexDay Proof
Havij - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHbajo ataqueremotewindows27 jun 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
CVE-2015-1701HIGHbajo ataqueransomwarelocalwindows24 jun 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.