Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Metasploit600
MS16-016 mrxdav.sys WebDav Local Privilege Escalation
CVE-2016-005109 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (1)
CVE-2016-0951doswindows09 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-856208 feb 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC
CVE-2015-8562 Exploit in bash
CVE-2015-856208 feb 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC41
Trigger and exploit code for CVE-2014-4113
CVE-2014-4113HIGHbajo ataque07 feb 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
VulnCheck XDB
local
CVE-2014-4113HIGHbajo ataque07 feb 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Metasploit600
Advantech WebAccess Dashboard Viewer uploadImageCommon Arbitrary File Upload
CVE-2016-085405 feb 2016
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RIESGO
abrir
Metasploit500
D-Link DSL-2750B OS Command Injection
CVE-2016-20017CRITICALbajo ataque05 feb 2016
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as
100RIESGO
abrir
Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
CVE-2023-38098HIGH04 feb 2016
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability
41RIESGO
abrir
Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
CVE-2016-152504 feb 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Metasploit300
NETGEAR ProSafe Network Management System 300 Authenticated File Download
CVE-2016-152404 feb 2016
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
CVE-2023-38096CRITICAL04 feb 2016
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability
65RIESGO
abrir
Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
CVE-2016-1525webappshardware04 feb 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Exploit-DBVexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-0861webappshardware04 feb 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
28RIESGO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-7246webappshardware04 feb 2016
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RIESGO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-7247webappshardware04 feb 2016
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and
28RIESGO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-7245webappshardware04 feb 2016
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RIESGO
abrir
Exploit-DBVexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-0862webappshardware04 feb 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir
Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
CVE-2016-1524webappshardware04 feb 2016
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2015-157903 feb 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
GitHub PoC31
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS
CVE-2015-157903 feb 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
GitHub PoC30
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS
CVE-2015-157903 feb 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
Exploit-DB
Viprinet Multichannel VPN Router 300 - Persistent Cross-Site Scripting
CVE-2014-2045webappshardware03 feb 2016
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-4594webappsjsp02 feb 2016
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-4592webappsjsp02 feb 2016
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-4593webappsjsp02 feb 2016
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ
23RIESGO
abrir
Metasploit600
lastore-daemon D-Bus Privilege Escalation
CVE-2016-15045HIGH02 feb 2016
Deepin lastore-daemon Privilege Escalation via Unsigned .deb Installation
36RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-4591webappsjsp02 feb 2016
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - javascript Code Execution
CVE-2015-2419HIGHbajo ataquelocalwindows01 feb 2016
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial o
83RIESGO
abrir
Exploit-DBVexDay Proof
iOS Kernel - IOReportHub Use-After-Free
CVE-2016-1719dosios28 ene 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RIESGO
abrir
anteriorpágina 1024 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.