Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
GitHub PoC
CVE-2015-0235
CVE-2015-023525 feb 2016
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Exploit-DB
IBM Lotus Domino R8 - Password Hash Extraction
CVE-2005-2428webappswindows25 feb 2016
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RIESGO
abrir
Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
CVE-2006-1794webappsphp24 feb 2016
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arb
23RIESGO
abrir
Exploit-DBVexDay Proof
libxml2 - xmlDictAddString Heap Buffer Overread
CVE-2016-1839doslinux24 feb 2016
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS befo
23RIESGO
abrir
GitHub PoC1
Elm0D/CVE-2017-8464
CVE-2017-8464HIGHbajo ataque24 feb 2016
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Exploit-DBVexDay Proof
libxml2 - xmlParserPrintFileContextInternal Heap Buffer Overread
CVE-2016-1838doslinux24 feb 2016
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 1
23RIESGO
abrir
Metasploit600
Jenkins XStream Groovy classpath Deserialization Vulnerability
CVE-2016-079224 feb 2016
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir
Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
CVE-2006-0871webappsphp24 feb 2016
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions all
23RIESGO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal
CVE-2016-4004webappswindows23 feb 2016
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Integer Overflow
CVE-2016-2399dosmultiple23 feb 2016
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to caus
23RIESGO
abrir
Exploit-DB
Ubuntu < 15.10 - PT Chown Arbitrary PTs Access Via User Namespace Privilege Escalation
CVE-2016-2856locallinux22 feb 2016
pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubun
23RIESGO
abrir
Exploit-DB
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
CVE-2016-1915webappsjava22 feb 2016
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4
23RIESGO
abrir
Exploit-DB
BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
CVE-2016-1914webappsjava22 feb 2016
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.x (Ubuntu 14.04 / Mint 17.3 / Fedora 22) - Double-free usb-midi SMEP Privilege Escalation
CVE-2016-2384locallinux22 feb 2016
Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows p
23RIESGO
abrir
GitHub PoC
glibc getaddrinfo stack-based buffer overflow
CVE-2015-754721 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-754721 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
PEAR LiveUser < 0.16.8 - Arbitrary File Access
CVE-2006-0869webappsphp21 feb 2016
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Reposito
23RIESGO
abrir
Exploit-DB
QuickHeal 16.00 - 'webssx.sys' Driver Denial of Service
CVE-2015-8285doswindows19 feb 2016
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
23RIESGO
abrir
Exploit-DB
AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation
CVE-2016-2853locallinux19 feb 2016
The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local user
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SimpleButton Creation Type Confusion
CVE-2015-8644dosmultiple19 feb 2016
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RIESGO
abrir
Exploit-DB
AUFS (Ubuntu 15.10) - 'allow_userns' Fuse/Xattr User Namespaces Privilege Escalation
CVE-2016-2854locallinux19 feb 2016
The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local use
23RIESGO
abrir
Exploit-DB
Geeklog < 1.4.0 - Multiple Vulnerabilities
CVE-2006-0823webappsphp19 feb 2016
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attacke
23RIESGO
abrir
GitHub PoC
glibc check and update in light of CVE-2015-7547
CVE-2015-754718 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC51
Automated Exploit Toolkit for CVE-2015-6095 and CVE-2016-0049
CVE-2016-004918 feb 2016
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
Exploit-DB
ADOdb < 4.71 - Cross Site Scripting
CVE-2006-0806webappsphp18 feb 2016
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow re
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - BitmapData.drawWithQuality Heap Overflow
CVE-2016-0964dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DB
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers
CVE-2015-2080remotemultiple17 feb 2016
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive informat
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - textfield Constructor Type Confusion
CVE-2016-0985dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Sound.loadPCMFromByteArray Dangling Pointer
CVE-2016-0984HIGHbajo ataquedosmultiple17 feb 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
83RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Heap Overflow
CVE-2016-0971dosmultiple17 feb 2016
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS
35RIESGO
abrir
anteriorpágina 1022 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.