Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5679remotehardware05 ago 2016
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticat
28RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5680remotehardware05 ago 2016
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance
28RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5678remotehardware05 ago 2016
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows re
23RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5676remotehardware05 ago 2016
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillanc
50RIESGO
abrir
Metasploit300
DLL Side Loading Vulnerability in VMware Host Guest Client Redirector
CVE-2016-533005 ago 2016
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 t
43RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5674remotehardware05 ago 2016
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR Rea
60RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5677remotehardware05 ago 2016
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.
28RIESGO
abrir
Metasploit600
NUUO NVRmini 2 / NETGEAR ReadyNAS Surveillance Unauthenticated Remote Code Execution
CVE-2016-567404 ago 2016
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR Rea
60RIESGO
abrir
Metasploit600
NUUO NVRmini 2 / Crystal / NETGEAR ReadyNAS Surveillance Authenticated Remote Code Execution
CVE-2016-567504 ago 2016
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 th
60RIESGO
abrir
Metasploit300
NUUO NVRmini 2 / NETGEAR ReadyNAS Surveillance Default Configuration Load and Administrator Password Reset
CVE-2016-567604 ago 2016
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillanc
50RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 1.12.0 < 1.12.12 / 2.0.0 < 2.0.4 - PacketBB Dissector Denial of Service
CVE-2016-6505dosmultiple03 ago 2016
epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.0.0 < 2.0.4 - CORBA IDL Dissectors Denial of Service
CVE-2016-6503doswindows_x86-6403 ago 2016
The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 1.12.0 < 1.12.12 - NDS Dissector Denial of Service
CVE-2016-6504dosmultiple03 ago 2016
epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.0.0 < 2.0.4 - MMSE / WAP / WBXML / WSP Dissectors Denial of Service
CVE-2016-6512dosmultiple03 ago 2016
epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, whi
23RIESGO
abrir
Exploit-DB
phpMyAdmin 4.6.2 - (Authenticated) Remote Code Execution
CVE-2016-5734webappsphp29 jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
Exploit-DB
Trend Micro Deep Discovery 3.7/3.8 SP1 (3.81)/3.8 SP2 (3.82) - 'hotfix_upload.cgi' Filename Remote Code Execution
CVE-2016-5840webappslinux29 jul 2016
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad
23RIESGO
abrir
Exploit-DB
AXIS (Multiple Products) - 'devtools ' (Authenticated) Remote Command Execution
CVE-2015-8257webappslinux29 jul 2016
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell
28RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1607webappsjava25 jul 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Sec
23RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1609webappsjava25 jul 2016
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP gettext 1.0.12 - 'gettext.php' Code Execution
CVE-2016-6175webappsphp25 jul 2016
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via
28RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1610webappsjava25 jul 2016
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo
28RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1608webappsjava25 jul 2016
vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated u
28RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 2 2.0.0.421/1.2 1.2.0.846 - Multiple Vulnerabilities
CVE-2016-1611webappsjava25 jul 2016
Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 5.5.37/5.6.23/7.0.8 - 'bzread()' Out-of-Bounds Write
CVE-2016-5399dosphp25 jul 2016
The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attac
23RIESGO
abrir
GitHub PoC1
linux 提权
CVE-2012-005622 jul 2016
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RIESGO
abrir
Metasploit600
SonicWall Global Management System XMLRPC set_time_zone Unauth RCE
CVE-2014-842022 jul 2016
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before
23RIESGO
abrir
VulnCheck XDB
local
CVE-2012-005622 jul 2016
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RIESGO
abrir
Exploit-DBVexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation
CVE-2016-6253localbsd21 jul 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RIESGO
abrir
GitHub PoC11
This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.
CVE-2006-618421 jul 2016
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RIESGO
abrir
Exploit-DB
Websphere/JBoss/OpenNMS/Symantec Endpoint Protection Manager - Java Deserialization Remote Code Execution
CVE-2015-4852CRITICALbajo ataqueremotemultiple20 jul 2016
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
anteriorpágina 1008 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.