Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9/10/11 - 'CDOMStringDataList::InitFromString' Out-of-Bounds Read (MS15-112)
CVE-2015-6086remotewindows14 abr 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - Out-of-Bounds Read Code Execution (MS16-042)
CVE-2016-0122localwindows14 abr 2016
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compa
35RIESGO
abrir
GitHub PoC3
这个代码包含了CVE-2015-8660漏洞的利用代码,还有注释,出现问题的源代码,打了补丁后的代码
CVE-2015-866014 abr 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
CVE-2016-0491webappsjsp13 abr 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
CVE-2016-0492webappsjsp13 abr 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - IMemory Native Interface is Insecure for IPC Use
CVE-2016-0846dosandroid11 abr 2016
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RIESGO
abrir
Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
CVE-2016-1593webappsjsp11 abr 2016
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RIESGO
abrir
Exploit-DB
Axis Network Cameras - Multiple Vulnerabilities
CVE-2015-8256webappshardware11 abr 2016
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.
35RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - IOMX 'getConfig'/'getParameter' Information Disclosure
CVE-2016-2417dosandroid11 abr 2016
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
23RIESGO
abrir
Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
CVE-2016-1594webappsjsp11 abr 2016
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RIESGO
abrir
Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
CVE-2016-1596webappsjsp11 abr 2016
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authentic
23RIESGO
abrir
Exploit-DB
Novell ServiceDesk 6.5/7.0.3/7.1.0 - Multiple Vulnerabilities
CVE-2016-1595webappsjsp11 abr 2016
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows rem
23RIESGO
abrir
GitHub PoC36
arbitrary memory read/write by IMemroy OOB
CVE-2016-084608 abr 2016
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RIESGO
abrir
Exploit-DB
Apple Intel HD 3000 Graphics Driver 10.0.0 - Local Privilege Escalation
CVE-2016-1743localosx08 abr 2016
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RIESGO
abrir
Metasploit600
op5 v7.1.9 Configuration Command Execution
CVE-2025-34115HIGH08 abr 2016
OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php
36RIESGO
abrir
Metasploit600
ExaGrid Known SSH Key and Default Password
CVE-2016-156007 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RIESGO
abrir
Metasploit600
ExaGrid Known SSH Key and Default Password
CVE-2016-156107 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RIESGO
abrir
Exploit-DBVexDay Proof
ExaGrid - Known SSH Key and Default Password (Metasploit)
CVE-2016-1561remotelinux07 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RIESGO
abrir
Exploit-DBVexDay Proof
ExaGrid - Known SSH Key and Default Password (Metasploit)
CVE-2016-1560remotelinux07 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RIESGO
abrir
Exploit-DB
Linux Kernel (x86) - Disable ASLR by Setting the RLIMIT_STACK Resource to Unlimited
CVE-2016-3672doslinux_x8606 abr 2016
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize t
23RIESGO
abrir
Exploit-DB
Panda Security URL Filtering < 4.3.1.9 - Local Privilege Escalation
CVE-2015-7378localwindows06 abr 2016
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and install
23RIESGO
abrir
Exploit-DB
Panda Endpoint Administration Agent < 7.50.00 - Local Privilege Escalation
CVE-2016-3943localwindows06 abr 2016
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a
23RIESGO
abrir
Metasploit600
Apache CouchDB Arbitrary Command Execution
CVE-2017-1263606 abr 2016
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir
Metasploit600
Apache CouchDB Arbitrary Command Execution
CVE-2017-1263506 abr 2016
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
Metasploit600
Apache Continuum Arbitrary Command Execution
CVE-2016-15057CRITICAL06 abr 2016
Apache Continuum: Command injection leading to RCE
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - MSHTML!CSVGHelpers::SetAttributeStringAndPointer Use-After-Free (MS16-023)
CVE-2016-0111doswindows05 abr 2016
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a
35RIESGO
abrir
GitHub PoC10
PoC attack server for CVE-2015-7547 buffer overflow vulnerability in glibc DNS stub resolver (public version)
CVE-2015-754705 abr 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-754705 abr 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys' Local Privilege Escalation (MS14-058)
CVE-2014-4113HIGHbajo ataquelocalwindows05 abr 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DB
Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow
CVE-2016-2233dosmultiple04 abr 2016
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
35RIESGO
abrir
anteriorpágina 1017 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.