Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
VulnCheck XDB
initial-access
CVE-2017-18368CRITICALbajo ataque30 mar 2016
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Object.unwatch Use-After-Free
CVE-2016-0998remotemultiple29 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir
Exploit-DBVexDay Proof
Cogent Datahub 7.3.9 Gamma Script - Local Privilege Escalation
CVE-2016-2288localwindows28 mar 2016
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - SUID Binary Logic Error Kernel Code Execution
CVE-2016-1757localmultiple23 mar 2016
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in AsBroadcaster.broadcastMessage UaF Fix
CVE-2016-0999doswindows23 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in Object.unwatch UaF Fix
CVE-2016-0998doswindows23 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Shape Rendering Crash
CVE-2016-1002doswindows23 mar 2016
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Code Execution Due to Lack of Bounds Checking in AppleUSBPipe::Abort
CVE-2016-1749dososx23 mar 2016
IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Zlib Codec Heap Overflow
CVE-2016-1001doswindows23 mar 2016
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Sprite Creation Use-After-Free
CVE-2016-1000doswindows23 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir
GitHub PoC
must run this native binary with system privilege
CVE-2014-432223 mar 2016
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - AppleKeyStore Use-After-Free
CVE-2016-1755dososx23 mar 2016
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Unchecked Array Index Used to Read Object Pointer Then Call Virtual Method in Nvidia Geforce Driver
CVE-2016-1741dososx23 mar 2016
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary c
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in MovieClip.swapDepths UaF Fix
CVE-2016-0997doswindows23 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir
GitHub PoC55
Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow
CVE-2013-202823 mar 2016
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Use-After-Free and Double Delete Due to Incorrect Locking in Intel GPU Driver
CVE-2016-1744dososx23 mar 2016
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RIESGO
abrir
Metasploit300
MS16-032 Secondary Logon Handle Privilege Escalation
CVE-2016-0099HIGHbajo ataqueransomware21 mar 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1/10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032)
CVE-2016-0099HIGHbajo ataqueransomwarelocalwindows_x8621 mar 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir
Exploit-DBVexDay Proof
Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass
CVE-2016-0793webappswindows20 mar 2016
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RIESGO
abrir
GitHub PoC
Cve-2015-1538-1
CVE-2015-153820 mar 2016
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
GitHub PoC
dachidahu/CVE-2016-0752
CVE-2016-0752HIGHbajo ataque18 mar 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
Exploit-DB
OpenSSH 7.2p1 - (Authenticated) xauth Command Injection
CVE-2016-3115MEDIUMremotemultiple16 mar 2016
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to
45RIESGO
abrir
Metasploit600
BMC Server Automation RSCD Agent NSH Remote Command Execution
CVE-2016-154216 mar 2016
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir
Metasploit600
BMC Server Automation RSCD Agent NSH Remote Command Execution
CVE-2016-154316 mar 2016
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RIESGO
abrir
Exploit-DB
Cisco UCS Manager 2.1(1b) - Remote Command Injection (Shellshock)
CVE-2014-6278HIGHbajo ataqueremotehardware16 mar 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD 10.2 (x64) - 'amd64_set_ldt' Heap Overflow
CVE-2016-1885dosfreebsd_x86-6416 mar 2016
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RIESGO
abrir
GitHub PoC7
a exploit for cve-2016-0728
CVE-2016-072815 mar 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
local
CVE-2016-072815 mar 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Metasploit600
Kaltura Remote PHP Code Execution
CVE-2016-15044CRITICAL15 mar 2016
Kaltura < 11.1.0-2 PHP Object Injection RCE
63RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout (MS16-023)
CVE-2016-0108doswindows14 mar 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
anteriorpágina 1019 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.