Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Microsoft Windows - VHDMP Arbitrary Physical Disk Cloning Privilege Escalation (MS16-138)
CVE-2016-7224localwindows15 nov 2016
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 151
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - VHDMP Arbitrary File Creation Privilege Escalation (MS16-138)
CVE-2016-7226localwindows15 nov 2016
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - MSHTML CMap­Element::Notify Use-After-Free (MS15-009)
CVE-2015-0040doswindows14 nov 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.4 (Ubuntu 16.04) - 'BPF' Local Privilege Escalation (Metasploit)
CVE-2016-4557locallinux14 nov 2016
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RIESGO
abrir
GitHub PoC
bluebluelan/CVE-2015-7547-proj-master
CVE-2015-754710 nov 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11/10/9 - MSHTML 'PROPERTYDESC::Handle­Style­Component­Property' Out-of-Bounds Read (MS16-104)
CVE-2016-3324doswindows10 nov 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-754710 nov 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC7
Exploit for Joomla 3.4.4 - 3.6.4 (CVE-2016-8869 and CVE-2016-8870)
CVE-2016-886910 nov 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft WININET.dll - 'CHttp­Header­Parser::Parse­Status­Line' Out-of-Bounds Read (MS16-104/MS16-105)
CVE-2016-3325doswindows10 nov 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted w
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Connect 9.5.7 - Cross-Site Scripting
CVE-2016-7851webappswindows09 nov 2016
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - LSASS SMB NTLM Exchange Null-Pointer Dereference (MS16-137)
CVE-2016-7237doswindows09 nov 2016
Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, W
35RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k' Denial of Service (MS16-135)
CVE-2016-7255HIGHbajo ataqueransomwaredoswindows09 nov 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
Metasploit600
Dlink DIR Routers Unauthenticated HNAP Login Stack Buffer Overflow
CVE-2016-656307 nov 2016
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RIESGO
abrir
Metasploit300
Zyxel/Eir D1000 DSL Modem NewNTPServer Command Injection Over TR-064
CVE-2016-1037207 nov 2016
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary c
40RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8/9/10/11 / IIS / CScript.exe/WScript.exe VBScript - CRegExp..Execute Use of Uninitialized Memory (MS14-080/MS14-084)
CVE-2014-6363remotewindows07 nov 2016
vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allo
28RIESGO
abrir
GitHub PoC
Recent Linux privilege escalation exploit
CVE-2016-5195HIGHbajo ataque06 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque06 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
IBM AIX 5.3/6.1/7.1/7.2 - 'lquerylv' Local Privilege Escalation
CVE-2016-6079localaix04 nov 2016
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to ob
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM AIX 6.1/7.1/7.2.0.2 - 'lsmcode' Local Privilege Escalation
CVE-2016-3053localaix04 nov 2016
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile
23RIESGO
abrir
Metasploit400
WinaXe 7.7 FTP Client Remote Buffer Overflow
CVE-2025-34107HIGH03 nov 2016
WinaXe 7.7 FTP Client Remote Buffer Overflow
36RIESGO
abrir
Exploit-DBVexDay Proof
Alienvault OSSIM/USM 5.3.1 - SQL Injection
CVE-2016-8582webappsphp02 nov 2016
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RIESGO
abrir
Exploit-DBVexDay Proof
Bassmaster 1.5.1 - Batch Arbitrary JavaScript Injection Remote Code Execution (Metasploit)
CVE-2014-7205remotelinux02 nov 2016
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9 - MSHTML CAttrArray Use-After-Free (MS14-056)
CVE-2014-4141doswindows02 nov 2016
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
GitHub PoC
Source code: https://github.com/XiphosResearch/exploits/tree/master/Joomraa
CVE-2016-886902 nov 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
Exploit-DB
Citrix Receiver/Receiver Desktop Lock 4.5 - Authentication Bypass
CVE-2016-9111localmultiple02 nov 2016
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
CVE-2015-1328locallinux02 nov 2016
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Exploit-DBVexDay Proof
Alienvault OSSIM/USM 5.3.1 - PHP Object Injection
CVE-2016-8580webappsphp02 nov 2016
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RIESGO
abrir
GitHub PoC5
firebroo/CVE-2016-6663
CVE-2016-666302 nov 2016
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB be
23RIESGO
abrir
Exploit-DBVexDay Proof
Alienvault OSSIM/USM 5.3.1 - Persistent Cross-Site Scripting
CVE-2016-8581webappsphp02 nov 2016
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Ubuntu / Fedora / RedHat) - 'Overlayfs' Local Privilege Escalation (Metasploit)
CVE-2015-8660locallinux02 nov 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
anteriorpágina 1000 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.