Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Django CMS 3.3.0 - Editor Snippet Persistent Cross-Site Scripting
CVE-2016-6186webappspython20 jul 2016
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/j
23RIESGO
abrir
Exploit-DB
OpenSSH 7.2p2 - Username Enumeration
CVE-2016-6210MEDIUMremotelinux20 jul 2016
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
Metasploit0
Oracle Weblogic Server Deserialization RCE - MarshalledObject
CVE-2016-351019 jul 2016
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12
40RIESGO
abrir
Exploit-DB
OpenSSHd 7.2p2 - Username Enumeration
CVE-2016-6210MEDIUMremotelinux18 jul 2016
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
Exploit-DB
Meinberg NTP Time Server ELX800/GPS M4x V5.30p - Remote Command Execution / Escalate Privileges
CVE-2016-3989remotehardware17 jul 2016
The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME
23RIESGO
abrir
Exploit-DB
Meinberg NTP Time Server ELX800/GPS M4x V5.30p - Remote Command Execution / Escalate Privileges
CVE-2016-3962remotehardware17 jul 2016
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RIESGO
abrir
GitHub PoC1
CVE-2016-3962-Exploit
CVE-2016-396217 jul 2016
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - DefineBitsJPEG2 Memory Corruption
CVE-2016-4179dosmultiple13 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (4)
CVE-2016-4208dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - TAG Memory Corruption
CVE-2016-4176dosmultiple13 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir
Exploit-DB
Apache Archiva 1.3.9 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2016-4469webappsxml13 jul 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (5)
CVE-2016-4207dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Secondary Logon Handle Privilege Escalation (MS16-032) (Metasploit)
CVE-2016-0099HIGHbajo ataqueransomwarelocalwindows13 jul 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (7)
CVE-2016-4201dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (1)
CVE-2016-4205dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - DefineSprite Memory Corruption
CVE-2016-4175dosmultiple13 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (6)
CVE-2016-4206dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - SceneAndFrameData Memory Corruption
CVE-2016-4177dosmultiple13 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-363613 jul 2016
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (3)
CVE-2016-4203dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (2)
CVE-2016-4204dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - LMZA Property Decoding Heap Corruption
CVE-2016-4137dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Overflow
CVE-2016-4135dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Exploit-DB
IPS Community Suite 4.1.12.3 - PHP Code Injection
CVE-2016-6174webappsphp11 jul 2016
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Image Packing Overflow
CVE-2016-4138dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - JXR Processing Double-Free
CVE-2016-4136dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 SP1 - 'mrxdav.sys' WebDAV Privilege Escalation (MS16-016) (Metasploit)
CVE-2016-0051localwindows11 jul 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Metasploit600
Tiki Wiki Unauthenticated File Upload Vulnerability
CVE-2025-34111CRITICAL11 jul 2016
Tiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE
63RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
CVE-2016-2098remoteruby11 jul 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC
KosukeShimofuji/CVE-2016-5734
CVE-2016-573408 jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
anteriorpágina 1009 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.