Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-0007localwindows25 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DBVexDay Proof
CesarFTP 0.99g - XCWD Denial of Service
CVE-2006-2961doswindows19 ene 2016
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - devenum.dll!DeviceMoniker::Load() Heap Corruption Buffer Underflow (MS16-007)
CVE-2016-0015doswindows13 ene 2016
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office / COM Object - 'WMALFXGFXDSP.dll' DLL Planting (MS16-007)
CVE-2016-0016doswindows13 ene 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash BlurFilter Processing - Out-of-Bounds Memset
CVE-2015-8636dosmultiple11 ene 2016
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro - node.js HTTP Server Listening on localhost Can Execute Commands
CVE-2016-3987remotewindows11 ene 2016
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (1)
CVE-2015-8635doswindows11 ene 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RIESGO
abrir
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.00 - CWD Command Overflow (SEH)
CVE-2015-7768remotewindows11 ene 2016
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free When Setting Stage
CVE-2015-8634doswindows_x86-6411 ene 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DCS-931L - Arbitrary File Upload (Metasploit)
CVE-2015-2049webappshardware07 ene 2016
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.3.3 (Ubuntu 14.04/15.10) - 'overlayfs' Local Privilege Escalation (1)
CVE-2015-8660locallinux05 ene 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
Exploit-DBVexDay Proof
pdfium - CPDF_Function::Call Stack Buffer Overflow
CVE-2015-6787dosmultiple04 ene 2016
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
pdfium - CPDF_DIBSource::DownSampleScanline32Bit Heap Out-of-Bounds Read
CVE-2015-6787dosmultiple04 ene 2016
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
CVE-2014-6287CRITICALbajo ataqueremotewindows04 ene 2016
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
Exploit-DBVexDay Proof
pdfium - CPDF_TextObject::CalcPositionData Heap Out-of-Bounds Read
CVE-2015-6787dosmultiple04 ene 2016
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - 'AirPDcapDecryptWPABroadcastKey' Heap Out-of-Bounds Read (1)
CVE-2015-8724dosmultiple22 dic 2015
The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - 'infer_pkt_encap' Heap Out-of-Bounds Read
CVE-2015-8733dosmultiple22 dic 2015
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Sound.setTransform - Use-After-Free
CVE-2015-8434doswindows_x86-6421 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.replaceText - Use-After-Free
CVE-2015-8424doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.setFormat - Use-After-Free
CVE-2015-8422doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash MovieClip.duplicateMovieClip - Use-After-Free
CVE-2015-8412doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.thickness Setter - Use-After-Free
CVE-2015-8421doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.sharpness Setter - Use-After-Free
CVE-2015-8420doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash MovieClip.startDrag - Use-After-Free
CVE-2015-8411doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 - 'win32k' Local Privilege Escalation (MS15-010)
CVE-2015-0057localwindows_x86-6418 dic 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.tabIndex Setter - Use-After-Free
CVE-2015-8431doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.text Setter - Use-After-Free
CVE-2015-8430doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash TextField.type Setter - Use-After-Free
CVE-2015-8429doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - TextField.Variable Setter Use-After-Free
CVE-2015-8427doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - 'TextField' Use-After Free
CVE-2015-8425doswindows18 dic 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.