Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Registry Hive Loading Relative Arbitrary Read in nt!RtlValidRelativeSecurityDescriptor (MS16-123)
CVE-2016-3376doswindows20 oct 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
28RIESGO
abrir
Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
CVE-2013-4863remotehardware20 oct 2016
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RIESGO
abrir
Exploit-DBVexDay Proof
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
CVE-2015-4624remotelinux20 oct 2016
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
CVE-2016-6255remotehardware20 oct 2016
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing win32k!sbit_Embolden / win32k!ttfdCloseFontContext Use-After-Free (MS16-120)
CVE-2016-7182doswindows20 oct 2016
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; W
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Function.apply' Information Leak (MS16-119)
CVE-2016-7194doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.map' Heap Overflow (MS16-119)
CVE-2016-7190doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.1/3.1.2 - File Enumeration / Path Traversal
CVE-2016-7982webappsphp20 oct 2016
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to en
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing RCVT TrueType Instruction Handler Out-of-Bounds Read (MS16-120)
CVE-2016-3209doswindows20 oct 2016
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure DACL Privilege Escalation (MS16-118)
CVE-2016-3388localwindows20 oct 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Spread Operator Stack Overflow (MS16-119)
CVE-2016-3386doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.2 - Cross-Site Request Forgery
CVE-2016-7980webappsphp20 oct 2016
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote a
23RIESGO
abrir
Exploit-DB
Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection
CVE-2016-3473webappsxml20 oct 2016
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0,
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)
CVE-2016-5195HIGHbajo ataquelocallinux19 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-7450CRITICALbajo ataque18 oct 2016
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
CVE-2011-1249localwindows_x8618 oct 2016
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DeviceApi CMApi PiCMOpenDeviceKey Arbitrary Registry Key Write Privilege Escalation (MS16-124)
CVE-2016-0075localwindows18 oct 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DFS Client Driver Arbitrary Drive Mapping Privilege Escalation (MS16-123)
CVE-2016-7185localwindows18 oct 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DeviceApi CMApi User Hive Impersonation Privilege Escalation (MS16-124)
CVE-2016-0073localwindows18 oct 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails - Dynamic Render File Upload / Remote Code Execution (Metasploit)
CVE-2016-0752HIGHbajo ataqueremotemultiple17 oct 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Diagnostics Hub - DLL Load Privilege Escalation (MS16-125)
CVE-2016-7188localwindows17 oct 2016
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RIESGO
abrir
GitHub PoC
Proof-of-Concept CVE-2016-0199
CVE-2016-019916 oct 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
Exploit-DB
Linux Kernel < 4.5.1 - Off-By-One (PoC)
CVE-2016-6187doslinux16 oct 2016
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RIESGO
abrir
Metasploit600
Ruby on Rails Dynamic Render File Upload Remote Code Execution
CVE-2016-0752HIGHbajo ataque16 oct 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
Metasploit600
PowerShellEmpire Arbitrary File Upload (Skywalker)
CVE-2024-6127CRITICAL15 oct 2016
BC Security Empire Path Traversal RCE
68RIESGO
abrir
GitHub PoC1
Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904
CVE-2008-293813 oct 2016
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RIESGO
abrir
GitHub PoC1
Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904
CVE-2016-124013 oct 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2013-486312 oct 2016
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Webex Player T29.10 - '.ARF' Out-of-Bounds Memory Corruption
CVE-2016-1415doswindows12 oct 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 23.0.0.162 - '.SWF' ConstantPool Critical Memory Corruption
CVE-2016-4273dosmultiple12 oct 2016
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637
28RIESGO
abrir
anteriorpágina 1003 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.