Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DB
Subversion 1.6.6/1.6.12 - Code Execution
CVE-2013-2088remotelinux12 oct 2016
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit perm
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2013-486312 oct 2016
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Webex Player T29.10 - '.ARF' Out-of-Bounds Memory Corruption
CVE-2016-1415doswindows12 oct 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 23.0.0.162 - '.SWF' ConstantPool Critical Memory Corruption
CVE-2016-4273dosmultiple12 oct 2016
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.1 - 'Recvmmsg' Local Privilege Escalation (Metasploit)
CVE-2014-0038locallinux11 oct 2016
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'gpsOneXtra' Data Files Denial of Service
CVE-2016-5348dosandroid11 oct 2016
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RIESGO
abrir
Metasploit0
Apache Tomcat on RedHat Based Systems Insecure Temp Config Privilege Escalation
CVE-2016-542510 oct 2016
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RIESGO
abrir
Metasploit600
Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability
CVE-2016-643310 oct 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir
Metasploit300
Cisco Firepower Management Console 6.0 Post Auth Report Download Directory Traversal
CVE-2016-643510 oct 2016
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RIESGO
abrir
Exploit-DB
Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
CVE-2016-4997locallinux10 oct 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RIESGO
abrir
Exploit-DB
Apache Tomcat 8/7/6 (RedHat Based Distros) - Local Privilege Escalation
CVE-2016-5425locallinux10 oct 2016
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RIESGO
abrir
Exploit-DB
HP Client 9.1/9.0/8.1/7.9 - Command Injection
CVE-2015-1497remotemultiple10 oct 2016
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
CVE-2016-6433webappscgi05 oct 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Hard-Coded MySQL Credentials
CVE-2016-6434locallinux05 oct 2016
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive
23RIESGO
abrir
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
CVE-2016-6435webappscgi05 oct 2016
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RIESGO
abrir
Exploit-DB
ISC BIND 9 - Denial of Service
CVE-2016-2776dosmultiple04 oct 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
Metasploit600
Disk Pulse Enterprise Login Buffer Overflow
CVE-2025-34108HIGH03 oct 2016
Disk Pulse Enterprise 9.0.34 Login Stack Buffer Overflow
36RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 8/7/6 (Debian-Based Distros) - Local Privilege Escalation
CVE-2016-1240locallinux03 oct 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
VulnCheck XDB
local
CVE-2016-4655MEDIUMbajo ataque02 oct 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
GitHub PoC103
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMbajo ataque02 oct 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
GitHub PoC
just some research notes
CVE-2015-386430 sep 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
GitHub PoC27
CVE-2016-2776
CVE-2016-277630 sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-277630 sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
Metasploit0
Apache Tomcat on Ubuntu Log Init Privilege Escalation
CVE-2016-124030 sep 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
Metasploit300
Cisco IKE Information Disclosure
CVE-2016-6415HIGHbajo ataque29 sep 2016
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir
Exploit-DB
Grandsteam GXV3611_HD - SQL Injection
CVE-2015-2866remotehardware29 sep 2016
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attacke
23RIESGO
abrir
Exploit-DB
Symantec Messaging Gateway 10.6.1 - Directory Traversal
CVE-2016-5312webappsjava28 sep 2016
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au
35RIESGO
abrir
GitHub PoC
KosukeShimofuji/CVE-2016-2776
CVE-2016-277628 sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
Exploit-DBVexDay Proof
Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit)
CVE-2015-3864remoteandroid27 sep 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Metasploit300
BIND TSIG Query Denial of Service
CVE-2016-277627 sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
anteriorpágina 1004 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.