Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Microsoft Edge - Internationalization Initialization Type Confusion (MS16-144)
CVE-2016-728721 dic 2016
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c
35RIESGO
abrir
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-1017521 dic 2016
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi
50RIESGO
abrir
Exploit-DB
Microsoft Edge - SIMD.toLocaleString Uninitialized Memory (MS16-145)
CVE-2016-728621 dic 2016
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
35RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - MSHTML CSplice­Tree­Engine::Remove­Splice Use-After-Free (MS14-035)
CVE-2014-178520 dic 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DB
Google Android - WifiNative::setHotlist Stack Overflow
CVE-2016-677220 dic 2016
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code wi
23RIESGO
abrir
Exploit-DB
Google Chrome < 31.0.1650.48 - HTTP 1xx base::String­Tokenizer­T<...>::Quick­Get­Next Out-of-Bounds Read
CVE-2013-662719 dic 2016
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RIESGO
abrir
Exploit-DB
Naenara Browser 3.5 (RedStar 3.0 Desktop) - 'JACKRABBIT' Client-Side Command Execution
CVE-2009-247718 dic 2016
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RIESGO
abrir
Exploit-DB
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
CVE-2014-6271CRITICALbajo ataque18 dic 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
CVE-2016-764416 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9 - IEFRAME CView::Ensure­Size Use-After-Free (MS13-021)
CVE-2013-0090HIGH16 dic 2016
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
53RIESGO
abrir
Exploit-DB
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
CVE-2016-763716 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Exploit-DB
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
CVE-2016-766116 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RIESGO
abrir
Exploit-DB
Nagios < 4.2.2 - Arbitrary Code Execution
CVE-2016-956515 dic 2016
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write
28RIESGO
abrir
Exploit-DB
Nagios < 4.2.4 - Local Privilege Escalation
CVE-2016-956615 dic 2016
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 9 - IEFRAME CMarkup::Remove­Pointer­Pos Use-After-Free (MS13-055)
CVE-2013-314315 dic 2016
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (mem
35RIESGO
abrir
Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
CVE-2016-995014 dic 2016
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and
23RIESGO
abrir
Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
CVE-2016-995114 dic 2016
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `Respawn
23RIESGO
abrir
Exploit-DB
APT - Repository Signing Bypass via Memory Allocation Failure
CVE-2016-125214 dic 2016
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1
23RIESGO
abrir
Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
CVE-2016-994914 dic 2016
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates t
28RIESGO
abrir
Exploit-DB
Adobe Animate 15.2.1.95 - Memory Corruption
CVE-2016-786614 dic 2016
Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitatio
28RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-801913 dic 2016
Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and ea
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-802513 dic 2016
SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authen
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-802013 dic 2016
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earl
28RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-802413 dic 2016
Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VS
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-802213 dic 2016
Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)
28RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-801713 dic 2016
Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows a
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-802113 dic 2016
Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-802313 dic 2016
Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-801813 dic 2016
Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)
23RIESGO
abrir
Exploit-DB
McAfee Virus Scan Enterprise for Linux 1.9.2 < 2.0.2 - Remote Code Execution
CVE-2016-801613 dic 2016
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote
23RIESGO
abrir
anteriorpágina 150 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.