Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-0006localwindows25 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-0007localwindows25 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
CVE-2016-0007localwindows25 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DB
Huawei Mate 7 - '/dev/hifi_misc' Privilege Escalation
CVE-2015-8088localhardware24 ene 2016
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2016-072823 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC
googleweb/CVE-2016-0728
CVE-2016-072823 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
local
CVE-2014-4113HIGHbajo ataque22 ene 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
GitHub PoC22
nardholio/cve-2016-0728
CVE-2016-072822 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-072822 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC5
Exploit CVE-2014-4113
CVE-2014-4113HIGHbajo ataque22 ene 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DB
NTP - Local Privilege Escalation
CVE-2016-0727locallinux21 ene 2016
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ub
23RIESGO
abrir
Metasploit600
Oracle ATS Arbitrary File Upload
CVE-2016-049220 ene 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Metasploit600
Oracle ATS Arbitrary File Upload
CVE-2016-049120 ene 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
GitHub PoC3
CVE-2016-0728 Linux Kernel Vulnerability
CVE-2016-072820 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2016-072820 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC1
idl3r/cve-2016-0728
CVE-2016-072819 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (2)
CVE-2016-0728locallinux19 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (1)
CVE-2016-0728locallinux19 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DBVexDay Proof
CesarFTP 0.99g - XCWD Denial of Service
CVE-2006-2961doswindows19 ene 2016
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RIESGO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-8283webappsphp18 ene 2016
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RIESGO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-8282webappsphp18 ene 2016
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
23RIESGO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-8284webappsphp18 ene 2016
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RIESGO
abrir
GitHub PoC67
PoC for CVE-2015-6086
CVE-2015-608618 ene 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RIESGO
abrir
Metasploit500
Windows Net-NTLMv2 Reflection DCOM/RPC (Juicy)
CVE-2016-322516 ene 2016
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RIESGO
abrir
Metasploit300
Windows Net-NTLMv2 Reflection DCOM/RPC
CVE-2016-322516 ene 2016
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RIESGO
abrir
Exploit-DB
mcart.xls Bitrix Module 6.5.2 - SQL Injection
CVE-2015-8356webappsphp15 ene 2016
Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u
23RIESGO
abrir
Exploit-DB
Roundcube Webmail 1.1.3 - Directory Traversal
CVE-2015-8770webappsphp15 ene 2016
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office / COM Object - 'WMALFXGFXDSP.dll' DLL Planting (MS16-007)
CVE-2016-0016doswindows13 ene 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
28RIESGO
abrir
Exploit-DB
WhatsUp Gold 16.3 - Remote Code Execution
CVE-2015-8261webappsasp13 ene 2016
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - devenum.dll!DeviceMoniker::Load() Heap Corruption Buffer Underflow (MS16-007)
CVE-2016-0015doswindows13 ene 2016
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RIESGO
abrir
anteriorpágina 1026 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.