Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Microsoft Windows - GDI+ ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)
CVE-2016-3303doswindows17 ago 2016
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - GDI+ EMR_EXTTEXTOUTA / EMR_POLYTEXTOUTA Heap Buffer Overflow (MS16-097)
CVE-2016-3304doswindows17 ago 2016
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - GDI+ DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)
CVE-2016-3301doswindows17 ago 2016
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
CVE-2016-3316dosmultiple16 ago 2016
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
CVE-2016-4312webappsjsp16 ago 2016
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Local File Inclusion
CVE-2016-4314webappsjsp16 ago 2016
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
CVE-2016-4311webappsjsp16 ago 2016
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - MSHTML!CMultiReadStreamLifetimeManager::ReleaseThreadStateInternal Read AV
CVE-2016-3288doswindows16 ago 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet E
35RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
CVE-2016-4316webappsjsp16 ago 2016
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
CVE-2016-4315webappsjsp16 ago 2016
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir
Exploit-DB
GitLab - 'impersonate' Feature Privilege Escalation
CVE-2016-4340webappsruby15 ago 2016
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8
28RIESGO
abrir
Exploit-DB
Claroline < 1.7.7 - Arbitrary File Inclusion
CVE-2006-4844webappsphp14 ago 2016
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeo
28RIESGO
abrir
Metasploit400
AF_PACKET chocobo_root Privilege Escalation
CVE-2016-865512 ago 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir
Metasploit300
ColoradoFTP Server 1.3 Build 8 Directory Traversal Information Disclosure
CVE-2025-34110CRITICAL11 ago 2016
ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
63RIESGO
abrir
Metasploit300
Zabbix toggle_ids SQL Injection
CVE-2016-1013411 ago 2016
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQ
40RIESGO
abrir
Exploit-DB
SquirrelMail < 1.4.7 - Arbitrary Variable Overwrite
CVE-2006-4019webappsphp11 ago 2016
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overw
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
CVE-2016-5847doslinux10 ago 2016
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
CVE-2016-5845doslinux10 ago 2016
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca
23RIESGO
abrir
Exploit-DB
vBulletin 5.2.2 - Server-Side Request Forgery
CVE-2016-6483webappsphp10 ago 2016
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Le
28RIESGO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6602webappsjsp10 ago 2016
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RIESGO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6603webappsjsp10 ago 2016
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Word 2007/2010/2013/2016 - Out-of-Bounds Read Code Execution (MS16-099)
CVE-2016-3313localwindows10 ago 2016
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote at
35RIESGO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6601webappsjsp10 ago 2016
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6600webappsjsp10 ago 2016
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot
60RIESGO
abrir
Exploit-DB
Xfinity Gateway (Technicolor DPC3941T) - Cross-Site Request Forgery
CVE-2016-7454webappshardware09 ago 2016
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r204217
23RIESGO
abrir
Metasploit300
Internet Explorer Iframe Sandbox File Name Disclosure Vulnerability
CVE-2016-332109 ago 2016
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the f
30RIESGO
abrir
Metasploit600
Trend Micro Smart Protection Server Exec Remote Code Injection
CVE-2016-626708 ago 2016
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330
30RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)
CVE-2016-3223localwindows08 ago 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RIESGO
abrir
Exploit-DBVexDay Proof
VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
CVE-2016-5330localwindows06 ago 2016
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 t
43RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5679remotehardware05 ago 2016
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticat
28RIESGO
abrir
anteriorpágina 1007 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.