Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-926928 nov 2016
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appli
28RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 10 - MSHTML 'CEdit­Adorner::Detach' Use-After-Free (MS13-047)
CVE-2013-312028 nov 2016
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 8 - MSHTML 'SRun­Pointer::Span­Qualifier/Run­Type' Out-Of-Bounds Read (MS15-009)
CVE-2015-005028 nov 2016
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memo
35RIESGO
abrir
Exploit-DB
NTP 4.2.8p3 - Denial of Service
CVE-2015-785528 nov 2016
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause
35RIESGO
abrir
Exploit-DB
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)
CVE-2016-5195HIGHbajo ataque27 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (1)
CVE-2016-7255HIGHbajo ataque24 nov 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
Exploit-DB
GNU Wget < 1.18 - Access List Bypass / Race Condition
CVE-2016-709824 nov 2016
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow
23RIESGO
abrir
Exploit-DB
Ubuntu 15.10 - 'USERNS ' Overlayfs Over Fuse Privilege Escalation
CVE-2016-157622 nov 2016
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which all
23RIESGO
abrir
Exploit-DB
Huawei UTPS - Unquoted Service Path Privilege Escalation
CVE-2016-876922 nov 2016
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the
23RIESGO
abrir
Exploit-DB
Crestron AM-100 - Multiple Vulnerabilities
CVE-2016-563922 nov 2016
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RIESGO
abrir
Exploit-DB
Microsoft Edge Scripting Engine - Memory Corruption (MS16-129)
CVE-2016-720221 nov 2016
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RIESGO
abrir
Exploit-DB
Microsoft Edge - 'CText­Extractor::Get­Block­Text' Out-of-Bounds Read (MS16-104)
CVE-2016-324721 nov 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RIESGO
abrir
Exploit-DB
D-Link DIR-Series Routers - HNAP Login Stack Buffer Overflow (Metasploit)
CVE-2016-656321 nov 2016
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RIESGO
abrir
Exploit-DB
NTP 4.2.8p8 - Denial of Service
CVE-2016-743421 nov 2016
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 8 - jscript 'Reg­Exp­Base::FBad­Header' Use-After-Free (MS15-018)
CVE-2015-248221 nov 2016
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 an
35RIESGO
abrir
Exploit-DB
Palo Alto Networks PanOS - 'root_trace' Local Privilege Escalation
CVE-2016-915118 nov 2016
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0
23RIESGO
abrir
Exploit-DB
Palo Alto Networks PanOS - appweb3 Stack Buffer Overflow
CVE-2016-915018 nov 2016
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x b
35RIESGO
abrir
Exploit-DB
Nagios 4.2.2 - Local Privilege Escalation
CVE-2016-8641MEDIUM18 nov 2016
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil
33RIESGO
abrir
Exploit-DB
Palo Alto Networks PanOS - 'root_reboot' Local Privilege Escalation
CVE-2016-915118 nov 2016
Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0
23RIESGO
abrir
Exploit-DB
Microsoft Edge - 'Array.reverse' Overflow
CVE-2016-720218 nov 2016
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RIESGO
abrir
Exploit-DB
Microsoft Edge - 'Array.splice' Heap Overflow
CVE-2016-720318 nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RIESGO
abrir
Exploit-DB
Moxa SoftCMS 1.5 - Denial of Service (PoC)
CVE-2016-933218 nov 2016
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate
23RIESGO
abrir
Exploit-DB
Microsoft Edge - 'Array.filter' Information Leak
CVE-2016-7200HIGHbajo ataque18 nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
Exploit-DB
Microsoft Edge - 'FillFromPrototypes' Type Confusion
CVE-2016-7201HIGHbajo ataque18 nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
Exploit-DB
Microsoft Edge - 'eval' Type Confusion
CVE-2016-724017 nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
35RIESGO
abrir
Exploit-DB
Nginx (Debian Based Distros + Gentoo) - 'logrotate' Local Privilege Escalation
CVE-2016-124716 nov 2016
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS
23RIESGO
abrir
Exploit-DB
Microsoft Windows - VHDMP Arbitrary File Creation Privilege Escalation (MS16-138)
CVE-2016-722615 nov 2016
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - Registry Hive Loading 'nt!RtlEqualSid' Out-of-Bounds Read (MS16-138)
CVE-2016-721615 nov 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissi
23RIESGO
abrir
Exploit-DB
Microsoft Windows - VHDMP ZwDeleteFile Arbitrary File Deletion Privilege Escalation (MS16-138)
CVE-2016-722515 nov 2016
Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to
23RIESGO
abrir
Exploit-DB
Microsoft Windows - VHDMP Arbitrary Physical Disk Cloning Privilege Escalation (MS16-138)
CVE-2016-722415 nov 2016
Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 151
23RIESGO
abrir
anteriorpágina 152 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.