Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
MS15-134 Microsoft Windows Media Center MCL Information Disclosure
CVE-2015-612708 dic 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-004108 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RIESGO
abrir
Metasploit300
Windows WMI Receive Notification Exploit
CVE-2016-0040HIGHbajo ataque04 dic 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
Metasploit300
Easy File Sharing HTTP Server 7.2 SEH Overflow
CVE-2018-905902 dic 2015
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Metasploit600
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALbajo ataque01 dic 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Metasploit600
Cambium ePMP1000 'ping' Shell via Command Injection (up to v2.5)
CVE-2017-525528 nov 2015
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir
Metasploit600
ABRT sosreport Privilege Escalation
CVE-2015-528723 nov 2015
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RIESGO
abrir
Metasploit600
Jenkins CLI RMI Java Deserialization Vulnerability
CVE-2015-810318 nov 2015
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir
Metasploit600
IBM WebSphere RCE Java Deserialization Vulnerability
CVE-2015-7450CRITICALbajo ataque06 nov 2015
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir
Metasploit300
OpenNMS Java Object Unserialization Remote Code Execution
CVE-2015-810306 nov 2015
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir
Metasploit600
vBulletin 5.1.2 Unserialize Code Execution
CVE-2015-780804 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir
Metasploit600
Atlassian HipChat for Jira Plugin Velocity Template Injection
CVE-2015-560328 oct 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir
Metasploit600
Joomla Content History SQLi Remote Code Execution
CVE-2015-785723 oct 2015
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir
Metasploit600
Joomla Content History SQLi Remote Code Execution
CVE-2015-785823 oct 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Metasploit600
Joomla Content History SQLi Remote Code Execution
CVE-2015-729723 oct 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Metasploit300
Joomla com_contenthistory Error-Based SQL Injection
CVE-2015-729722 oct 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Metasploit0
Safari User-Assisted Applescript Exec Attack
CVE-2015-700716 oct 2015
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RIESGO
abrir
Metasploit300
Limesurvey Unauthenticated File Download
CVE-2025-34120HIGH12 oct 2015
LimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup Payload
36RIESGO
abrir
Metasploit600
Wordpress Ajax Load More PHP Upload Vulnerability
CVE-2015-10140HIGH10 oct 2015
Ajax Load More < 2.8.1.2 - Subscriber+ File Upload & Deletion
36RIESGO
abrir
Metasploit300
ManageEngine ServiceDesk Plus Path Traversal
CVE-2011-275703 oct 2015
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir
Metasploit300
PDF Shaper Buffer Overflow
CVE-2025-34106HIGH03 oct 2015
PDF Shaper v3.5/3.6 Buffer Overflow via Convert to Image Feature
36RIESGO
abrir
Metasploit300
Mac OS X 10.9.5 / 10.10.5 - rsh/libmalloc Privilege Escalation
CVE-2015-588901 oct 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir
Metasploit300
Apache James Server 2.3.2 Insecure User Creation Arbitrary File Write
CVE-2015-761101 oct 2015
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RIESGO
abrir
Metasploit600
Vtiger CRM - Authenticated Logo Upload RCE
CVE-2015-600028 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RIESGO
abrir
Metasploit600
Vtiger CRM - Authenticated Logo Upload RCE
CVE-2016-171328 sep 2015
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir
Metasploit300
PCMan FTP Server 2.0.7 Directory Traversal Information Disclosure
CVE-2015-760128 sep 2015
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..//
50RIESGO
abrir
Metasploit300
BisonWare BisonFTP Server 3.5 Directory Traversal Information Disclosure
CVE-2015-760228 sep 2015
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (d
50RIESGO
abrir
Metasploit300
Kaseya VSA Master Administrator Account Creation
CVE-2015-692223 sep 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir
Metasploit600
Kaseya VSA uploader.aspx Arbitrary File Upload
CVE-2015-692223 sep 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir
Metasploit300
Konica Minolta FTP Utility 1.00 Directory Traversal Information Disclosure
CVE-2015-760322 sep 2015
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.