Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.400exploits catalogados
37.193CVEs con explotación pública
24.695probados en laboratorio
80.401 exploits
Exploit-DB
Apache Archiva 1.3.9 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2016-4469webappsxml13 jul 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (1)
CVE-2016-4205dosmultiple13 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - DefineSprite Memory Corruption
CVE-2016-4175dosmultiple13 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 22.0.0.192 - TAG Memory Corruption
CVE-2016-4176dosmultiple13 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - LMZA Property Decoding Heap Corruption
CVE-2016-4137dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Overflow
CVE-2016-4135dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
CVE-2016-2098remoteruby11 jul 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Exploit-DB
IPS Community Suite 4.1.12.3 - PHP Code Injection
CVE-2016-6174webappsphp11 jul 2016
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 SP1 - 'mrxdav.sys' WebDAV Privilege Escalation (MS16-016) (Metasploit)
CVE-2016-0051localwindows11 jul 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - JXR Processing Double-Free
CVE-2016-4136dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
Metasploit600
Tiki Wiki Unauthenticated File Upload Vulnerability
CVE-2025-34111CRITICAL11 jul 2016
Tiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE
63RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Image Packing Overflow
CVE-2016-4138dosmultiple11 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
GitHub PoC
KosukeShimofuji/CVE-2016-5734
CVE-2016-573408 jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
Metasploit500
NetBSD mail.local Privilege Escalation
CVE-2016-625307 jul 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RIESGO
abrir
Exploit-DBVexDay Proof
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution
CVE-2016-4971remotelinux06 jul 2016
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir
Metasploit300
WebNMS Framework Server Arbitrary Text File Download
CVE-2016-660104 jul 2016
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir
Metasploit300
WebNMS Framework Server Credential Disclosure
CVE-2016-660204 jul 2016
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RIESGO
abrir
Metasploit300
WebNMS Framework Server Credential Disclosure
CVE-2016-660104 jul 2016
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir
Metasploit600
WebNMS Framework Server Arbitrary File Upload
CVE-2016-660004 jul 2016
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot
60RIESGO
abrir
Exploit-DB
Python smtplib 2.7.11 / 3.4.4 / 3.5.1 - Man In The Middle StartTLS Stripping
CVE-2016-0772localmultiple03 jul 2016
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an e
28RIESGO
abrir
GitHub PoC
CVE-2016-4971 written in nodejs
CVE-2016-497102 jul 2016
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir
GitHub PoC1
JBoss Autopwn CVE-2010-0738 JBoss authentication bypass
CVE-2010-0738MEDIUMbajo ataqueransomware02 jul 2016
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir
Exploit-DBVexDay Proof
Ktools Photostore 4.7.5 - Blind SQL Injection
CVE-2016-4337webappsphp30 jun 2016
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RIESGO
abrir
GitHub PoC363
Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431
CVE-2015-663930 jun 2016
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RIESGO
abrir
Exploit-DB
Microsoft Windows 7 SP1 (x86) - Local Privilege Escalation (MS16-014)
CVE-2016-0400localwindows_x8629 jun 2016
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
CVE-2016-2207dosmultiple29 jun 2016
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - PowerPoint Misaligned Stream-cache Remote Stack Buffer Overflow (PoC)
CVE-2016-2209dosmultiple29 jun 2016
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - 'dec2lha Library' Remote Stack Buffer Overflow (PoC)
CVE-2016-2210dosmultiple29 jun 2016
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - TNEF Decoder Integer Overflow
CVE-2016-3645dosmultiple29 jun 2016
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
CVE-2016-3652webappsphp29 jun 2016
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RIESGO
abrir
anteriorpágina 1010 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.