Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DB
Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation
CVE-2016-8869webappsphp27 oct 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
GitHub PoC
Check the Browser's FlashPlayer version to check if it is vulnerable to exploit CVE-2016-7855
CVE-2016-7855HIGHbajo ataque26 oct 2016
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linu
76RIESGO
abrir
Exploit-DB
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW PTRACE_POKEDATA' Race Condition (Write Access Method)
CVE-2016-5195HIGHbajo ataquelocallinux26 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Metasploit300
Joomla Account Creation and Privilege Escalation
CVE-2016-886925 oct 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
Metasploit300
Joomla Account Creation and Privilege Escalation
CVE-2016-887025 oct 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
Exploit-DB
Microsoft Windows (x86) - 'NDISTAPI' Local Privilege Escalation (MS11-062)
CVE-2011-1974localwindows_x8624 oct 2016
NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Serve
23RIESGO
abrir
GitHub PoC32
Universal Android root tool based on CVE-2016-5195. Watch this space.
CVE-2016-5195HIGHbajo ataque24 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC341
A CVE-2016-5195 exploit example.
CVE-2016-5195HIGHbajo ataque23 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque23 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque22 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque22 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC10
Mitigates CVE-2016-5195 aka DirtyCOW
CVE-2016-5195HIGHbajo ataque22 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC7
Dirty COW (CVE-2016-5195) vulnerability testing utility for Linux-based systems.
CVE-2016-5195HIGHbajo ataque22 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC513
PoC for Dirty COW (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque22 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Ansible playbook to mitigate CVE-2016-5195 on CentOS
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 (x86/x64) - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (SUID Method)
CVE-2016-5195HIGHbajo ataquelocallinux21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
CVE-2014-6271CRITICALbajo ataqueremotehardware21 oct 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC13
CVE-2016-5195 exploit written in Crystal
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC1012
CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Dirty Cow
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
RealPlayer 18.1.5.705 - '.QCP' Crash (PoC)
CVE-2016-9018doswindows21 oct 2016
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and c
23RIESGO
abrir
GitHub PoC1
ASRTeam/CVE-2016-5195
CVE-2016-5195HIGHbajo ataque21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.2 - Cross-Site Request Forgery
CVE-2016-7980webappsphp20 oct 2016
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote a
23RIESGO
abrir
Exploit-DB
Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection
CVE-2016-3473webappsxml20 oct 2016
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0,
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure Boundary Descriptor Privilege Escalation (MS16-118)
CVE-2016-3387localwindows20 oct 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RIESGO
abrir
Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
CVE-2016-6255remotehardware20 oct 2016
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
28RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
CVE-2016-7998webappsphp20 oct 2016
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP
28RIESGO
abrir
anteriorpágina 1002 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.