Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Pool-Based Buffer Overflow (MS16-026)
CVE-2016-0121doswindows14 mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout (MS16-023)
CVE-2016-0108doswindows14 mar 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Stack Corruption (MS16-026)
CVE-2016-0120doswindows14 mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0-229.x (CentOS / RHEL 7.1) - 'snd-usb-audio' Crash (PoC)
CVE-2016-2184doslinux14 mar 2016
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.
23RIESGO
abrir
Exploit-DBVexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-7563webappsphp14 mar 2016
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the aut
23RIESGO
abrir
Exploit-DBVexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-7564webappsphp14 mar 2016
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0-229.x (CentOS / RHEL 7.1) - 'iowarrior' Driver Crash (PoC)
CVE-2016-2188doslinux14 mar 2016
The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximat
23RIESGO
abrir
GitHub PoC8
PoC exploit server for CVE-2015-7547
CVE-2015-754710 mar 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
libotr 4.1.0 - Memory Corruption
CVE-2016-2851dosmultiple10 mar 2016
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of serv
28RIESGO
abrir
Exploit-DBVexDay Proof
Exim < 4.86.2 - Local Privilege Escalation
CVE-2016-1531locallinux10 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir
Exploit-DB
Putty pscp 0.66 - Stack Buffer Overwrite
CVE-2016-2563dosmultiple10 mar 2016
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows r
35RIESGO
abrir
Metasploit600
Exim "perl_startup" Privilege Escalation
CVE-2016-153110 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-754710 mar 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'aiptek' Nullpointer Dereference
CVE-2015-7515doslinux09 mar 2016
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-3135doslinux09 mar 2016
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-3134doslinux09 mar 2016
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local us
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'Wacom' Multiple Nullpointer Dereferences
CVE-2016-3139doslinux09 mar 2016
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor clie_5_attach Nullpointer Dereference
CVE-2015-7566doslinux09 mar 2016
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'mct_u232' Nullpointer Dereference
CVE-2016-3136doslinux09 mar 2016
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically p
23RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.84-3 - Local Privilege Escalation
CVE-2016-1531locallinux09 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Digital Editions 4.5.0 - '.pdf' Critical Memory Corruption
CVE-2016-0954doswindows09 mar 2016
Adobe Digital Editions before 4.5.1 allows attackers to execute arbitrary code or cause a denial of service (memory corr
28RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor 'treo_attach' Nullpointer Dereference
CVE-2016-2782doslinux09 mar 2016
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attack
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'digi_acceleport' Nullpointer Dereference
CVE-2016-3140doslinux09 mar 2016
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically p
23RIESGO
abrir
GitHub PoC
JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation vulnerability as discovered by Minded Security
CVE-2010-0738MEDIUMbajo ataqueransomware08 mar 2016
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir
Exploit-DBVexDay Proof
ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution
CVE-2016-2539webappsphp07 mar 2016
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Avast! - Authenticode Parsing Memory Corruption
CVE-2016-3986doswindows07 mar 2016
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RIESGO
abrir
Exploit-DB
McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass
CVE-2016-3984localwindows07 mar 2016
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.
23RIESGO
abrir
Exploit-DB
McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass
CVE-2016-4534localwindows07 mar 2016
The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on W
23RIESGO
abrir
GitHub PoC
Script to test vulnarability for CVE-2015-0235
CVE-2015-023507 mar 2016
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
Microsoft Windows 7 (x64) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
CVE-2014-1767localwindows_x86-6407 mar 2016
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RIESGO
abrir
anteriorpágina 1020 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.