Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DB
MySQL / MariaDB / PerconaDB 5.5.51/5.6.32/5.7.14 - Code Execution / Privilege Escalation
CVE-2016-6662locallinux12 sep 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
GitHub PoC33
Verification tools for CVE-2016-1287
CVE-2016-128708 sep 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Method Calls Use-After-Free
CVE-2016-4231dosmultiple08 sep 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Transform.colorTranform Getter Infomation Leak
CVE-2016-4232dosmultiple08 sep 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
35RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - libutils UTF16 to UTF8 Conversion Heap Buffer Overflow
CVE-2016-3861remoteandroid08 sep 2016
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
CVE-2016-4264webappsmultiple07 sep 2016
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attack
35RIESGO
abrir
Exploit-DB
glibc - 'getaddrinfo' Remote Stack Buffer Overflow
CVE-2015-7547remotelinux06 sep 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Metasploit500
Grandstream GXV31XX 'settimezone' Unauthenticated Command Execution
CVE-2019-1065501 sep 2016
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Selection.setFocus Use-After-Free
CVE-2016-4227dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MovieClip Transform Getter Use-After-Free
CVE-2016-4230dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free When Returning Rectangle
CVE-2016-4228dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Stage.align Setter Use-After-Free
CVE-2016-4226dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
GitHub PoC2
CVE-2014-6332 ZeroDay POC - Starts PowerShell
CVE-2014-6332HIGHbajo ataque29 ago 2016
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - BitmapData.copyPixels Use-After-Free
CVE-2016-4229dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DB
CubeCart < 3.0.12 - Multiple Vulnerabilities
CVE-2006-4525webappsphp28 ago 2016
Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote
23RIESGO
abrir
Metasploit0
WebKit not_number defineProperties UAF
CVE-2016-4657HIGHbajo ataque25 ago 2016
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
Metasploit0
WebKit not_number defineProperties UAF
CVE-2016-4656HIGHbajo ataque25 ago 2016
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir
Metasploit400
Safari Webkit JIT Exploit for iOS 7.1.2
CVE-2018-416225 ago 2016
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
30RIESGO
abrir
Metasploit400
Safari Webkit JIT Exploit for iOS 7.1.2
CVE-2016-466925 ago 2016
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir
Metasploit0
WebKit not_number defineProperties UAF
CVE-2016-4655MEDIUMbajo ataque25 ago 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
Exploit-DBVexDay Proof
Eye of Gnome 3.10.2 - GMarkup Out of Bounds Write
CVE-2016-6855doslinux23 ago 2016
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib befor
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
CVE-2016-6897webappsphp22 ago 2016
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
CVE-2016-6896webappsphp22 ago 2016
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RIESGO
abrir
Exploit-DBVexDay Proof
Ocomon 2.0 - SQL Injection
CVE-2005-4664webappsphp22 ago 2016
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir
Exploit-DB
Fortigate Firewalls - 'EGREGIOUSBLUNDER' Remote Code Execution
CVE-2016-6909webappshardware19 ago 2016
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9
35RIESGO
abrir
Exploit-DB
Watchguard Firewalls - 'ESCALATEPLOWMAN' ifconfig Privilege Escalation
CVE-2016-7089locallinux19 ago 2016
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifco
23RIESGO
abrir
Exploit-DB
Cisco ASA / PIX - 'EPICBANANA' Local Privilege Escalation
CVE-2016-6367HIGHbajo ataquelocalhardware19 ago 2016
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows loc
76RIESGO
abrir
Exploit-DB
X-Cart < 4.1.3 - Arbitrary Variable Overwrite
CVE-2006-4904webappsphp18 ago 2016
Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to o
23RIESGO
abrir
Exploit-DB
Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass
CVE-2016-6366HIGHbajo ataqueremotehardware18 ago 2016
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir
Exploit-DB
Linux Kernel - TCP Related Read Use-After-Free
CVE-2016-6828doslinux18 ago 2016
The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certai
23RIESGO
abrir
anteriorpágina 1006 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.