Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
CVE-2016-095610 feb 2016
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RIESGO
abrir
Exploit-DB
Microsoft Windows 7 SP1 (x86) - 'WebDAV' Local Privilege Escalation (MS16-016) (1)
CVE-2016-005110 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-757010 feb 2016
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbou
23RIESGO
abrir
Exploit-DB
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (1)
CVE-2016-095109 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
Exploit-DB
Adobe Photoshop CC / Bridge CC - '.iff' Parsing Memory Corruption
CVE-2016-095309 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
Exploit-DB
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
CVE-2016-095209 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
Exploit-DB
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-086104 feb 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
28RIESGO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-724504 feb 2016
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RIESGO
abrir
Exploit-DB
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-086204 feb 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir
Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
CVE-2016-152404 feb 2016
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
CVE-2016-152504 feb 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-724704 feb 2016
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and
28RIESGO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-724604 feb 2016
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RIESGO
abrir
Exploit-DB
Viprinet Multichannel VPN Router 300 - Persistent Cross-Site Scripting
CVE-2014-204503 feb 2016
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-459302 feb 2016
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-459202 feb 2016
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-459402 feb 2016
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a
23RIESGO
abrir
Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
CVE-2015-459102 feb 2016
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - javascript Code Execution
CVE-2015-2419HIGHbajo ataque01 feb 2016
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial o
83RIESGO
abrir
Exploit-DB
Apple Mac OSX Kernel - Hypervisor Driver Use-After-Free
CVE-2015-707828 ene 2016
Use-after-free vulnerability in Hypervisor in Apple OS X before 10.11.2 allows local users to gain privileges via vector
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - 'IOBluetoothHCIUserClient' Arbitrary Kernel Code Execution
CVE-2015-710828 ene 2016
The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of serv
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - IOSCSIPeripheralDeviceType00 Userclient Type 12 Kernel NULL Dereference
CVE-2015-706828 ene 2016
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to exe
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - 'gst_configure' Kernel Buffer Overflow
CVE-2015-707728 ene 2016
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - 'IOHDIXControllerUserClient::convertClient' Buffer Integer Overflow
CVE-2015-699528 ene 2016
The Disk Images component in Apple iOS before 9.1 and OS X before 10.11.1 misparses images, which allows attackers to ex
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - io_service_close Use-After-Free
CVE-2016-172028 ene 2016
IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cau
23RIESGO
abrir
Exploit-DB
Apple Mac OSX / iOS - Multiple Kernel Uninitialized Variable Bugs Leading to Code Execution Vulnerabilities
CVE-2016-172128 ene 2016
The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges o
23RIESGO
abrir
Exploit-DB
SAP HANA 1.00.095 - hdbindexserver Memory Corruption
CVE-2015-798628 ene 2016
The index server (hdbindexserver) in SAP HANA 1.00.095 allows remote attackers to execute arbitrary code or cause a deni
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - OSMetaClassBase::safeMetaCast in IOAccelContext2::connectClient NULL Dereference
CVE-2015-699628 ene 2016
IOAcceleratorFamily in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows attackers to execute a
23RIESGO
abrir
Exploit-DB
Apple Mac OSX / iOS - Double-Delete IOHIDEventQueue::start Code Execution
CVE-2015-711228 ene 2016
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attacke
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - IOBluetoothHCIPacketLogUserClient Memory Corruption
CVE-2015-704728 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
anteriorpágina 168 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.