Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Image Read
CVE-2016-0965dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
GitHub PoC1
t0r0t0r0/CVE-2015-7547
CVE-2015-754717 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC5
test script for CVE-2015-7547
CVE-2015-754717 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - H264 File Stack Corruption
CVE-2016-0967dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - LoadVars.decode Use-After-Free
CVE-2016-0974dosmultiple17 feb 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RIESGO
abrir
GitHub PoC1
Heartbleed
CVE-2014-0160HIGHbajo ataque16 feb 2016
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (1)
CVE-2018-4878HIGHbajo ataqueransomwarelocalwindows16 feb 2016
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DBVexDay Proof
glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)
CVE-2015-7547doslinux16 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
CVE-2014-1767localwindows_x8615 feb 2016
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Kerberos Security Feature Bypass (MS16-014)
CVE-2016-0049localwindows15 feb 2016
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
GitHub PoC16
CVE-2016-1287 vulnerability test
CVE-2016-128715 feb 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RIESGO
abrir
Metasploit600
Primefaces Remote Code Execution Exploit
CVE-2017-1000486CRITICALbajo ataque15 feb 2016
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
Metasploit600
Xymon useradm Command Execution
CVE-2016-205614 feb 2016
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RIESGO
abrir
Metasploit600
Ubiquiti airOS Arbitrary File Upload
CVE-2015-9266CRITICAL13 feb 2016
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RIESGO
abrir
Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (2)
CVE-2018-4878HIGHbajo ataqueransomwarelocalwindows13 feb 2016
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC
Gitlabpro/The-analysis-of-the-cve-2015-8651
CVE-2015-8651HIGHbajo ataque12 feb 2016
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and bef
83RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7568webappsphp10 feb 2016
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the a
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 SP1 (x86) - 'WebDAV' Local Privilege Escalation (MS16-016) (1)
CVE-2016-0051localwindows_x8610 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7570webappsphp10 feb 2016
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbou
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-754710 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7571webappsphp10 feb 2016
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin
23RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7572webappsphp10 feb 2016
20RIESGO
abrir
GitHub PoC543
Proof of concept for CVE-2015-7547
CVE-2015-754710 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7567webappsphp10 feb 2016
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw
23RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7569webappsphp10 feb 2016
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary S
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
CVE-2016-0956webappsmultiple10 feb 2016
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.iff' Parsing Memory Corruption
CVE-2016-0953doswindows09 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
CVE-2016-0952doswindows09 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
VulnCheck XDB
local
CVE-2016-005109 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Metasploit600
MS16-016 mrxdav.sys WebDav Local Privilege Escalation
CVE-2016-005109 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
anteriorpágina 1023 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.