Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Metasploit300
BIND TSIG Query Denial of Service
CVE-2016-277627 sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
GitHub PoC
whiteHat001/cve-2010-3333
CVE-2010-3333HIGHbajo ataque26 sep 2016
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
CVE-2016-3371localwindows26 sep 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
CVE-2016-3373localwindows26 sep 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RIESGO
abrir
GitHub PoC3
这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件
CVE-2012-1889HIGHbajo ataque25 sep 2016
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2012-1889HIGHbajo ataque25 sep 2016
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir
Metasploit600
MagniComp SysInfo mcsiwrapper Privilege Escalation
CVE-2017-651623 sep 2016
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Crash When Freeing Memory After AVC decoding
CVE-2016-4275dosmultiple23 sep 2016
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RIESGO
abrir
Exploit-DB
Exponent CMS 2.3.9 - Blind SQL Injection
CVE-2016-7400webappsphp22 sep 2016
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
CVE-2016-3237localwindows22 sep 2016
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RIESGO
abrir
Exploit-DBVexDay Proof
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
CVE-2016-5725doswindows22 sep 2016
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-5309dosmultiple21 sep 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
CVE-2016-3357doswindows21 sep 2016
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RIESGO
abrir
Exploit-DBVexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-5310dosmultiple21 sep 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2016-666220 sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2016-6366HIGHbajo ataque20 sep 2016
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir
GitHub PoC9
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.
CVE-2016-666220 sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
GitHub PoC163
Public repository for improvements to the EXTRABACON exploit
CVE-2016-6366HIGHbajo ataque20 sep 2016
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
CVE-2016-7083doswindows19 sep 2016
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
CVE-2016-7084doswindows19 sep 2016
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RIESGO
abrir
Metasploit600
BuilderEngine Arbitrary File Upload Vulnerability and execution
CVE-2025-34100CRITICAL18 sep 2016
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RIESGO
abrir
GitHub PoC
research CVE-2016-6662
CVE-2016-666216 sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
Exploit-DBVexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
CVE-2016-6253localnetbsd_x8615 sep 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RIESGO
abrir
GitHub PoC1
Simple ansible playbook to patch mysql servers against CVE-2016-6662
CVE-2016-666215 sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
GitHub PoC
MySQL server CVE-2016-6662 patch playbook
CVE-2016-666214 sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-6853webappslinux13 sep 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can
23RIESGO
abrir
Exploit-DBVexDay Proof
Cherry Music 0.35.1 - Arbitrary File Disclosure
CVE-2015-8309webappsphp13 sep 2016
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RIESGO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-6851webappslinux13 sep 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RIESGO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-6854webappslinux13 sep 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RIESGO
abrir
Exploit-DB
Open-Xchange App Suite 7.8.2 - Cross-Site Scripting
CVE-2016-5740webappslinux13 sep 2016
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RIESGO
abrir
anteriorpágina 1005 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.