Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in Serialization with ObjectEncoder.dynamicPropertyWriter
CVE-2015-7648dosmultiple14 dic 2015
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in IExternalizable.readExternal When Performing Local Serialization
CVE-2015-7647dosmultiple14 dic 2015
Adobe Flash Player before 18.0.0.255 and 19.x before 19.0.0.226 on Windows and OS X and before 11.2.202.540 on Linux all
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office / COM Object - 'els.dll' DLL Planting (MS15-134)
CVE-2015-6128remotewindows09 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - '.Link' File Incorrectly Resolved Reference (MS15-134)
CVE-2015-6127remotewindows09 dic 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-6133localwindows08 dic 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-6128localwindows08 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allo
60RIESGO
abrir
Exploit-DBVexDay Proof
Atlassian HipChat for Jira Plugin - Velocity Template Injection (Metasploit)
CVE-2015-5603remotemultiple08 dic 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-0041localwindows08 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-0100localwindows08 dic 2015
Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges v
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2015-6132localwindows08 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office - OLE Multiple DLL Side Loading Vulnerabilities (MS15-132/MS16-014/MS16-025/MS16-041/MS16-070) (Metasploit)
CVE-2016-3235HIGHbajo ataquelocalwindows08 dic 2015
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RIESGO
abrir
Exploit-DBVexDay Proof
Oracle BeeHive 2 - 'voice-servlet processEvaluation()' Write File (Metasploit)
CVE-2010-4417remotewindows03 dic 2015
Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2
60RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotecgi02 dic 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-7196remotecgi02 dic 2015
20RIESGO
abrir
Exploit-DBVexDay Proof
Man-db 2.6.7.1 - Local Privilege Escalation
CVE-2015-1336locallinux02 dic 2015
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t
23RIESGO
abrir
Exploit-DBVexDay Proof
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
CVE-2015-5287HIGHbajo ataquelocalmultiple01 dic 2015
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir
Exploit-DBVexDay Proof
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
CVE-2015-5273localmultiple01 dic 2015
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation
CVE-2015-5287HIGHbajo ataquelocallinux01 dic 2015
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir
Exploit-DBVexDay Proof
SAP Sybase Adaptive Server Enterprise - XML External Entity Information Disclosure
CVE-2013-6025remotemultiple25 nov 2015
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to re
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Race Condition DestroySMWP Use-After-Free (MS15-115)
CVE-2015-6101doswindows23 nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'ndis.sys' IOCTL 0x170034 (ndis!ndisNsiGetIfNameForIfIndex) Pool Buffer Overflow (MS15-117)
CVE-2015-6098doswindows23 nov 2015
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows S
23RIESGO
abrir
Exploit-DBVexDay Proof
vBulletin 5.x - Remote Code Execution
CVE-2015-7808webappsphp23 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Cursor Object Memory Leak (MS15-115)
CVE-2015-6102doswindows23 nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7857remotephp23 nov 2015
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7858remotephp23 nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Exploit-DBVexDay Proof
Nvidia Stereoscopic 3D Driver Service 7.17.13.5382 - Arbitrary Run Key Creation
CVE-2015-7865localwindows23 nov 2015
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Device Contexts and NtGdiSelectBitmap Use-After-Free (MS15-115)
CVE-2015-6100doswindows23 nov 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
CVE-2015-7297remotephp23 nov 2015
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Exploit-DBVexDay Proof
Chkrootkit - Local Privilege Escalation (Metasploit)
CVE-2014-0476locallinux20 nov 2015
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome - open-vcdiff Out-of-Bounds Read in Browser Process Integer Overflow
CVE-2015-6763doslinux_x8619 nov 2015
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.