Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
GitHub PoC1
A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)
CVE-2016-209807 jun 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Exploit-DB
Valve Steam 3.42.16.13 - Local Privilege Escalation
CVE-2016-5237localwindows06 jun 2016
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m
23RIESGO
abrir
Metasploit600
Tiki-Wiki CMS Calendar Command Execution
CVE-2025-34113HIGH06 jun 2016
Tiki Wiki CMS Authenticated Command Injection in Calendar Module
36RIESGO
abrir
Exploit-DB
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
CVE-2014-6278HIGHbajo ataquewebappscgi06 jun 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Metasploit400
Linux Kernel 4.6.3 Netfilter Privilege Escalation
CVE-2016-499703 jun 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RIESGO
abrir
Metasploit400
Linux Kernel 4.6.3 Netfilter Privilege Escalation
CVE-2016-499803 jun 2016
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local
18RIESGO
abrir
Exploit-DB
Liferay CE < 6.2 CE GA6 - Persistent Cross-Site Scripting
CVE-2016-3670webappsjsp02 jun 2016
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1
23RIESGO
abrir
Metasploit600
ActiveMQ web shell upload
CVE-2016-3088CRITICALbajo ataque01 jun 2016
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
Metasploit600
Apache Struts REST Plugin With Dynamic Method Invocation Remote Code Execution
CVE-2016-308701 jun 2016
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir
Metasploit600
WordPress WP Mobile Detector 3.5 Shell Upload
CVE-2016-15043CRITICAL31 may 2016
WP Mobile Detector <= 3.5 - Arbitrary File Upload
43RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector A.09.00 - Encrypted Communications Arbitrary Command Execution (Metasploit)
CVE-2016-2004remotewindows31 may 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir
GitHub PoC4
MySQL DoS in the Procedure Analyse Function – CVE-2015-4870
CVE-2015-487030 may 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RIESGO
abrir
Exploit-DB
MySQL 5.5.45 - procedure analyse Function Denial of Service
CVE-2015-4870dosmultiple30 may 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-3153HIGHbajo ataque29 may 2016
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC
towelroot
CVE-2014-3153HIGHbajo ataque29 may 2016
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - 'SETFKEY' (PoC)
CVE-2016-1886dosfreebsd_x86-6429 may 2016
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before
23RIESGO
abrir
Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 x64) - 'sendmsg' Kernel Heap Overflow (PoC)
CVE-2016-1887dosfreebsd_x86-6429 may 2016
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p1
23RIESGO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.2.1 - 'DecodeAdpcmImaQT' Buffer Overflow
CVE-2016-5108doswindows27 may 2016
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allo
28RIESGO
abrir
Exploit-DB
Micro Focus Rumba+ 9.4 - Multiple Stack Buffer Overflow Vulnerabilities
CVE-2016-1606doswindows26 may 2016
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attacke
35RIESGO
abrir
Exploit-DBVexDay Proof
HP Data Protector A.09.00 - Arbitrary Command Execution
CVE-2016-2004remotewindows26 may 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir
GitHub PoC6
Magento Unauthorized Remote Code Execution (CVE-2016-4010)
CVE-2016-401025 may 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-0491remotejava25 may 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-0492remotejava25 may 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection
CVE-2016-2386CRITICALbajo ataquewebappsxml19 may 2016
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime - '.mov' Parsing Memory Corruption
CVE-2016-1848dososx19 may 2016
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
CVE-2016-2388MEDIUMbajo ataquewebappsxml19 may 2016
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RIESGO
abrir
GitHub PoC86
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182818 may 2016
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
CVE-2016-4010webappsphp18 may 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir
Exploit-DB
SAP xMII 15.0 - Directory Traversal
CVE-2016-2389webappsjava17 may 2016
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow in Processing Raw 565 Textures
CVE-2016-1103dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
anteriorpágina 1013 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.