Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Adobe Flash - SetNative Use-After-Free
CVE-2016-110617 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
SAP xMII 15.0 - Directory Traversal
CVE-2016-238917 may 2016
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI
50RIESGO
abrir
Exploit-DB
Adobe Flash - Type Confusion in FileReference Constructor
CVE-2016-110517 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
CVE-2016-017017 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
Exploit-DB
Adobe Flash - Heap Overflow in ATF Processing Image Reading
CVE-2016-110117 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Symantec/Norton AntiVirus - ASPack Remote Heap/Pool Memory Corruption
CVE-2016-220817 may 2016
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RIESGO
abrir
Exploit-DB
Adobe Flash - addProperty Use-After-Free
CVE-2016-410817 may 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Exploit-DB
Meteocontrol WEB’log - Admin Password Disclosure (Metasploit)
CVE-2016-229617 may 2016
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RIESGO
abrir
Exploit-DB
Microsoft Windows - 'gdi32.dll' Multiple 'EMF COMMENT_MULTIFORMATS' Record Handling (MS16-055)
CVE-2016-016917 may 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir
Exploit-DB
Apple OS X 10.10.5 - 'rootsh' Local Privilege Escalation
CVE-2016-182816 may 2016
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
Exploit-DB
eXtplorer 2.1.9 - '.ZIP' Directory Traversal
CVE-2016-431316 may 2016
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DB
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-480716 may 2016
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS
23RIESGO
abrir
Exploit-DB
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-480816 may 2016
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack
23RIESGO
abrir
Exploit-DB
CakePHP Framework 3.2.4 - IP Spoofing
CVE-2016-479316 may 2016
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RIESGO
abrir
Exploit-DB
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-480616 may 2016
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RIESGO
abrir
Exploit-DB
Microsoft Windows Media Center - '.MCL' File Processing Remote Code Execution (MS16-059)
CVE-2016-0185HIGHbajo ataque12 may 2016
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary
83RIESGO
abrir
Exploit-DB
Google Android Broadcom Wi-Fi Driver - Memory Corruption
CVE-2016-080111 may 2016
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir
Exploit-DB
Adobe Reader DC 15.010.20060 - Memory Corruption
CVE-2016-107710 may 2016
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro
28RIESGO
abrir
Exploit-DB
Microsoft Windows 7 - 'WebDAV' Local Privilege Escalation (MS16-016) (2)
CVE-2016-005109 may 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DB
ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)
CVE-2016-3714HIGHbajo ataque09 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
Exploit-DB
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (2)
CVE-2016-101306 may 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RIESGO
abrir
Exploit-DB
DotNetNuke 07.04.00 - Administration Authentication Bypass
CVE-2015-279406 may 2016
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RIESGO
abrir
Exploit-DB
Adobe Flash - MovieClip.duplicateMovieClip Use-After-Free
CVE-2016-101106 may 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RIESGO
abrir
Exploit-DB
Linux Kernel 4.4.x (Ubuntu 16.04) - 'double-fdput()' bpf(BPF_PROG_LOAD) Privilege Escalation
CVE-2016-455704 may 2016
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RIESGO
abrir
Exploit-DB
McAfee LiveSafe 14.0 - Relocations Processing Memory Corruption
CVE-2016-453504 may 2016
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RIESGO
abrir
Exploit-DB
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
CVE-2015-602304 may 2016
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir
Exploit-DB
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
CVE-2016-278404 may 2016
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduc
23RIESGO
abrir
Exploit-DB
WordPress Plugin Ninja Forms 2.9.36 < 2.9.42 - File Upload (Metasploit)
CVE-2016-120904 may 2016
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RIESGO
abrir
Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
CVE-2016-3714HIGHbajo ataque04 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
Exploit-DB
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
CVE-2015-602404 may 2016
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir
anteriorpágina 162 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.