Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataque10 jun 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Apple Mac OSX Kernel - Null Pointer Dereference in AppleMuxControl.kext
CVE-2016-179410 jun 2016
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attack
23RIESGO
abrir
Exploit-DB
Apple Mac OSX Kernel - NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value
CVE-2016-180310 jun 2016
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2016-133707 jun 2016
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requ
23RIESGO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2015-640207 jun 2016
Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11,
23RIESGO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2015-640107 jun 2016
Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication re
23RIESGO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2016-132807 jun 2016
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RIESGO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2016-133607 jun 2016
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RIESGO
abrir
Exploit-DB
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
CVE-2014-6278HIGHbajo ataque06 jun 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
Exploit-DB
Liferay CE < 6.2 CE GA6 - Persistent Cross-Site Scripting
CVE-2016-367002 jun 2016
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1
23RIESGO
abrir
Exploit-DB
HP Data Protector A.09.00 - Encrypted Communications Arbitrary Command Execution (Metasploit)
CVE-2016-200431 may 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir
Exploit-DB
MySQL 5.5.45 - procedure analyse Function Denial of Service
CVE-2015-487030 may 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RIESGO
abrir
Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 x64) - 'sendmsg' Kernel Heap Overflow (PoC)
CVE-2016-188729 may 2016
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p1
23RIESGO
abrir
Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - 'SETFKEY' (PoC)
CVE-2016-188629 may 2016
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before
23RIESGO
abrir
Exploit-DB
VideoLAN VLC Media Player 2.2.1 - 'DecodeAdpcmImaQT' Buffer Overflow
CVE-2016-510827 may 2016
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allo
28RIESGO
abrir
Exploit-DB
Micro Focus Rumba+ 9.4 - Multiple Stack Buffer Overflow Vulnerabilities
CVE-2016-160626 may 2016
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attacke
35RIESGO
abrir
Exploit-DB
HP Data Protector A.09.00 - Arbitrary Command Execution
CVE-2016-200426 may 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir
Exploit-DB
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-049125 may 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Exploit-DB
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-049225 may 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection
CVE-2016-2386CRITICALbajo ataque19 may 2016
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Apple QuickTime - '.mov' Parsing Memory Corruption
CVE-2016-184819 may 2016
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
CVE-2016-2388MEDIUMbajo ataque19 may 2016
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RIESGO
abrir
Exploit-DB
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
CVE-2016-401018 may 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir
Exploit-DB
Microsoft Windows - 'gdi32.dll' Multiple 'EMF CREATECOLORSPACEW' Record Handling (MS16-055)
CVE-2016-016817 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
Exploit-DB
Adobe Flash - SetNative Use-After-Free
CVE-2016-110617 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Adobe Flash - Type Confusion in FileReference Constructor
CVE-2016-110517 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Meteocontrol WEB’log - Admin Password Disclosure (Metasploit)
CVE-2016-229617 may 2016
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RIESGO
abrir
Exploit-DB
Adobe Flash - Heap Overflow in ATF Processing Image Reading
CVE-2016-110117 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Adobe Flash - addProperty Use-After-Free
CVE-2016-410817 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
CVE-2016-017017 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
anteriorpágina 161 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.