Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit0
ManageEngine OpManager Remote Code Execution
CVE-2015-776514 sep 2015
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RIESGO
abrir
Metasploit0
ManageEngine OpManager Remote Code Execution
CVE-2015-776614 sep 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir
Metasploit600
MS15-100 Microsoft Windows Media Center MCL Vulnerability
CVE-2015-250908 sep 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir
Metasploit600
F5 iControl iCall::Script Root Command Execution
CVE-2015-362803 sep 2015
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
Metasploit600
Nibbleblog File Upload Vulnerability
CVE-2015-696701 sep 2015
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir
Metasploit300
Boxoft WAV to MP3 Converter v1.1 Buffer Overflow
CVE-2015-724331 ago 2015
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir
Metasploit600
WordPress Responsive Thumbnail Slider Arbitrary File Upload
CVE-2015-10144HIGH28 ago 2015
Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
36RIESGO
abrir
Metasploit600
phpFileManager 0.9.8 Remote Code Execution
CVE-2015-595828 ago 2015
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
23RIESGO
abrir
Metasploit600
MVPower DVR Shell Unauthenticated Command Execution
CVE-2016-20016CRITICAL23 ago 2015
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir
Metasploit300
Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow
CVE-2015-776823 ago 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir
Metasploit600
ManageEngine ServiceDesk Plus Arbitrary File Upload
CVE-2019-8394HIGHbajo ataque20 ago 2015
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via l
98RIESGO
abrir
Metasploit600
Apache ActiveMQ 5.x-5.11.1 Directory Traversal Shell Upload
CVE-2015-183019 ago 2015
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir
Metasploit300
WordPress Symposium Plugin SQL Injection
CVE-2015-652218 ago 2015
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RIESGO
abrir
Metasploit600
CMS Bolt File Upload Vulnerability
CVE-2015-730917 ago 2015
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authent
50RIESGO
abrir
Metasploit300
Android Stagefright MP4 tx3g Integer Overflow
CVE-2015-386413 ago 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Metasploit300
Path Traversal in Oracle GlassFish Server Open Source Edition
CVE-2017-100002808 ago 2015
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
Metasploit300
PCMAN FTP Server Buffer Overflow - PUT Command
CVE-2013-473007 ago 2015
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
CVE-2015-462401 ago 2015
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
CVE-2015-462401 ago 2015
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
CVE-2015-148631 jul 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
CVE-2015-148931 jul 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir
Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
CVE-2015-148731 jul 2015
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir
Metasploit300
Heroes of Might and Magic III .h3m Map file Buffer Overflow
CVE-2025-34124HIGH29 jul 2015
Heroes of Might and Magic III .h3m Map File Buffer Overflow
36RIESGO
abrir
Metasploit300
Moxa Device Credential Retrieval
CVE-2016-9361CRITICAL28 jul 2015
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RIESGO
abrir
Metasploit300
BIND TKEY Query Denial of Service
CVE-2015-547728 jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Metasploit500
Libuser roothelper Privilege Escalation
CVE-2015-324524 jul 2015
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Metasploit500
Libuser roothelper Privilege Escalation
CVE-2015-324624 jul 2015
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RIESGO
abrir
Metasploit500
Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation
CVE-2015-376021 jul 2015
dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to g
18RIESGO
abrir
Metasploit0
ManageEngine EventLog Analyzer Remote Code Execution
CVE-2015-738711 jul 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Metasploit0
MS15-078 Microsoft Windows Font Driver Buffer Overflow
CVE-2015-2426HIGHbajo ataque11 jul 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.