Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit0
ManageEngine EventLog Analyzer Remote Code Execution
CVE-2015-738711 jul 2015
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir
Metasploit300
Accellion FTA 'statecode' Cookie Arbitrary File Read
CVE-2015-285610 jul 2015
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices
30RIESGO
abrir
Metasploit600
X11 Keyboard Command Injection
CVE-1999-052610 jul 2015
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RIESGO
abrir
Metasploit600
Accellion FTA getStatus verify_oauth_token Command Execution
CVE-2015-285710 jul 2015
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir
Metasploit500
Western Digital Arkeia Remote Code Execution
CVE-2015-770910 jul 2015
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir
Metasploit300
OpenSSL Alternative Chains Certificate Forgery MITM Proxy
CVE-2015-179309 jul 2015
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RIESGO
abrir
Metasploit500
Adobe Flash Player ByteArray Use After Free
CVE-2015-5119HIGHbajo ataque06 jul 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Metasploit500
Adobe Flash opaqueBackground Use After Free
CVE-2015-5122HIGHbajo ataque06 jul 2015
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir
Metasploit500
Apple OS X Entitlements Rootpipe Privilege Escalation
CVE-2015-367301 jul 2015
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RIESGO
abrir
Metasploit600
Watchguard XCS Remote Command Execution
CVE-2015-545329 jun 2015
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RIESGO
abrir
Metasploit600
Endian Firewall Proxy Password Change Command Injection
CVE-2015-508228 jun 2015
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir
Metasploit400
Pallete Projects Werkzeug Debugger Remote Code Execution
CVE-2024-34069HIGH28 jun 2015
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
36RIESGO
abrir
Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVE-2015-3043HIGHbajo ataque23 jun 2015
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir
Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
CVE-2015-3113HIGHbajo ataque23 jun 2015
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir
Metasploit400
Overlayfs Privilege Escalation
CVE-2015-132816 jun 2015
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Metasploit400
Overlayfs Privilege Escalation
CVE-2015-866016 jun 2015
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
Metasploit600
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution
CVE-2015-322416 jun 2015
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
Metasploit300
D-Link Cookie Command Execution
CVE-2025-34125CRITICAL12 jun 2015
D-Link DSP-W110A1 Cookie Command Injection
63RIESGO
abrir
Metasploit300
SysAid Help Desk Administrator Account Creation
CVE-2015-299303 jun 2015
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir
Metasploit300
SysAid Help Desk Database Credentials Disclosure
CVE-2015-299803 jun 2015
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Metasploit300
SysAid Help Desk Arbitrary File Download
CVE-2015-299703 jun 2015
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account
50RIESGO
abrir
Metasploit300
SysAid Help Desk Database Credentials Disclosure
CVE-2015-299603 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Metasploit300
SysAid Help Desk Arbitrary File Download
CVE-2015-299603 jun 2015
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir
Metasploit600
SysAid Help Desk Administrator Portal Arbitrary File Upload
CVE-2015-299403 jun 2015
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir
Metasploit600
SysAid Help Desk 'rdslogs' Arbitrary File Upload
CVE-2015-299503 jun 2015
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir
Metasploit300
PhoenixContact PLC Remote START/STOP Command
CVE-2014-919520 may 2015
Phoenix Contact Software ProConOs and MultiProg Missing Authentication for Critical Function
85RIESGO
abrir
Metasploit300
Windows ClientCopyImage Win32k Exploit
CVE-2015-1701HIGHbajo ataqueransomware12 may 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
Metasploit500
Adobe Flash Player Drawing Fill Shader Memory Corruption
CVE-2015-310512 may 2015
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466
60RIESGO
abrir
Metasploit500
Adobe Flash Player ShaderJob Buffer Overflow
CVE-2015-309012 may 2015
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir
Metasploit300
Realtek SDK Miniigd UPnP SOAP Command Execution
CVE-2014-8361CRITICALbajo ataque24 abr 2015
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.