Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DB
Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow
CVE-2016-2233dosmultiple04 abr 2016
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
35RIESGO
abrir
Exploit-DB
DameWare Remote Controller < 12.0.0.520 - Remote Code Execution
CVE-2016-2345remotewindows03 abr 2016
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows rem
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - URLStream.readObject Use-After-Free
CVE-2015-8048dosmultiple01 abr 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DB
PHP 5.5.33/7.0.4 - SNMP Format String
CVE-2016-4071remotemultiple01 abr 2016
Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20,
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - textfield.maxChars Use-After-Free
CVE-2015-8426dosmultiple01 abr 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Bitmap Use-After-Free
CVE-2016-0094doswindows01 abr 2016
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtGdiGetTextExtentExW' Out-of-Bounds Memory Read
CVE-2016-0093doswindows01 abr 2016
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Color.setTransform Use-After-Free
CVE-2015-5574dosmultiple01 abr 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and
35RIESGO
abrir
Exploit-DBVexDay Proof
Apache Jetspeed - Arbitrary File Upload (Metasploit)
CVE-2016-0709remotejava31 mar 2016
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3
60RIESGO
abrir
Exploit-DB
Apache OpenMeetings 1.9.x < 3.1.0 - '.ZIP' File Directory Traversal
CVE-2016-0784webappslinux31 mar 2016
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1
35RIESGO
abrir
Exploit-DBVexDay Proof
Apache Jetspeed - Arbitrary File Upload (Metasploit)
CVE-2016-0710remotejava31 mar 2016
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RIESGO
abrir
Metasploit600
Novell ServiceDesk Authenticated File Upload
CVE-2016-159330 mar 2016
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-232130 mar 2016
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-0160HIGHbajo ataque30 mar 2016
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Kamailio 4.3.4 - Heap Buffer Overflow
CVE-2016-2385doslinux30 mar 2016
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER a
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-822530 mar 2016
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-18368CRITICALbajo ataque30 mar 2016
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque30 mar 2016
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-163530 mar 2016
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALbajo ataque30 mar 2016
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime < 7.7.79.80.95 - '.FPX' Parsing Memory Corruption (2)
CVE-2016-1768dosmultiple30 mar 2016
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime < 7.7.79.80.95 - '.FPX' Parsing Memory Corruption (1)
CVE-2016-1767dosmultiple30 mar 2016
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple QuickTime < 7.7.79.80.95 - '.PSD' Parsing Memory Corruption
CVE-2016-1769dosmultiple30 mar 2016
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Exploit-DB
Google Android 5.0.1 - Metaphor Stagefright (ASLR Bypass)
CVE-2015-3864remoteandroid30 mar 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-20016CRITICAL30 mar 2016
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-757730 mar 2016
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-999530 mar 2016
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2011-331530 mar 2016
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x befor
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6278HIGHbajo ataque30 mar 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2001-053730 mar 2016
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RIESGO
abrir
anteriorpágina 1018 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.