Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DBVexDay Proof
Symantec/Norton AntiVirus - ASPack Remote Heap/Pool Memory Corruption
CVE-2016-2208dosmultiple17 may 2016
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF CREATECOLORSPACEW' Record Handling (MS16-055)
CVE-2016-0168doswindows17 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
Metasploit600
Magento 2.0.6 Unserialize Remote Code Execution
CVE-2016-401017 may 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
CVE-2016-0170dosmultiple17 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in FileReference Constructor
CVE-2016-1105dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Meteocontrol WEB’log - Admin Password Disclosure (Metasploit)
CVE-2016-2296webappsmultiple17 may 2016
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - JXR Processing Out-of-Bounds Read
CVE-2016-1102dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Heap Overflow in ATF Processing Image Reading
CVE-2016-1101dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF COMMENT_MULTIFORMATS' Record Handling (MS16-055)
CVE-2016-0169doswindows17 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SetNative Use-After-Free
CVE-2016-1106dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read when Placing Object
CVE-2016-1104dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DBVexDay Proof
Cisco ASA Software 8.x/9.x - IKEv1 / IKEv2 Buffer Overflow
CVE-2016-1287remotehardware17 may 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RIESGO
abrir
Exploit-DB
SAP xMII 15.0 - Directory Traversal
CVE-2016-2389webappsjava17 may 2016
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI
50RIESGO
abrir
Exploit-DBVexDay Proof
Dell SonicWALL Scrutinizer 11.01 - methodDetail SQL Injection (Metasploit)
CVE-2014-4977remotemultiple17 may 2016
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - '.MP4' Stack Corruption
CVE-2016-1096dosmultiple17 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Apple OS X 10.10.5 - 'rootsh' Local Privilege Escalation
CVE-2016-1828localosx16 may 2016
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4807webappspython16 may 2016
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS
23RIESGO
abrir
Exploit-DB
CakePHP Framework 3.2.4 - IP Spoofing
CVE-2016-4793webappsphp16 may 2016
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RIESGO
abrir
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4806webappspython16 may 2016
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RIESGO
abrir
Exploit-DB
eXtplorer 2.1.9 - '.ZIP' Directory Traversal
CVE-2016-4313webappsphp16 may 2016
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4808webappspython16 may 2016
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack
23RIESGO
abrir
GitHub PoC
Test modified buggy poc
CVE-2016-080115 may 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir
GitHub PoC15
Microsoft Office / COM Object DLL Planting
CVE-2015-613214 may 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - '.MCL' File Processing Remote Code Execution (MS16-059)
CVE-2016-0185HIGHbajo ataqueremotewindows12 may 2016
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary
83RIESGO
abrir
GitHub PoC78
abdsec/CVE-2016-0801
CVE-2016-080111 may 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir
Exploit-DB
Google Android Broadcom Wi-Fi Driver - Memory Corruption
CVE-2016-0801dosandroid11 may 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Reader DC 15.010.20060 - Memory Corruption
CVE-2016-1077dosmultiple10 may 2016
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro
28RIESGO
abrir
Metasploit300
Internet Explorer 11 VBScript Engine Memory Corruption
CVE-2016-0189HIGHbajo ataqueransomware10 may 2016
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 - 'WebDAV' Local Privilege Escalation (MS16-016) (2)
CVE-2016-0051localwindows09 may 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DBVexDay Proof
ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)
CVE-2016-3714HIGHbajo ataquelocalmultiple09 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
anteriorpágina 1014 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.