Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
iOS Kernel - IOHIDEventService Use-After-Free
CVE-2016-171928 ene 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RIESGO
abrir
Exploit-DB
iOS Kernel - AppleOscarCMA Use-After-Free
CVE-2016-171928 ene 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - 'IntelAccelerator::gstqConfigure' Kernel NULL Dereference
CVE-2015-710628 ene 2016
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RIESGO
abrir
Exploit-DB
Apple Mac OSX / iOS Kernel - iokit Registry Iterator Manipulation Double-Free
CVE-2015-708428 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - IOBluetoothHCIPacketLogUserClient Memory Corruption
CVE-2015-704728 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - 'IOBluetoothHCIUserClient' Arbitrary Kernel Code Execution
CVE-2015-710828 ene 2016
The Bluetooth HCI interface in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial of serv
23RIESGO
abrir
Exploit-DB
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
CVE-2015-704728 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
Exploit-DB
Apple Mac OSX / iOS - Unsandboxable Kernel Code Exection Due to iokit Double Release in IOKit
CVE-2015-708428 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - 'gst_configure' Kernel Buffer Overflow
CVE-2015-707728 ene 2016
The Intel Graphics Driver component in Apple OS X before 10.11.2 allows local users to gain privileges or cause a denial
23RIESGO
abrir
Exploit-DB
Apple Mac OSX Kernel - IOAccelMemoryInfoUserClient Use-After-Free
CVE-2015-704728 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
Exploit-DB
iOS Kernel - AppleOscarAccelerometer Use-After-Free
CVE-2016-171928 ene 2016
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RIESGO
abrir
Exploit-DB
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers
CVE-2015-704728 ene 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RIESGO
abrir
Exploit-DB
Apple Mac OSX - IOSCSIPeripheralDeviceType00 Userclient Type 12 Kernel NULL Dereference
CVE-2015-706828 ene 2016
IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to exe
23RIESGO
abrir
Exploit-DB
Linux Kernel 3.x/4.x - prima WLAN Driver Heap Overflow
CVE-2015-056925 ene 2016
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka W
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
CVE-2016-000725 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-000625 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DB
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-000725 ene 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RIESGO
abrir
Exploit-DB
FreeBSD SCTP ICMPv6 - Error Processing
CVE-2016-187925 ene 2016
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, w
28RIESGO
abrir
Exploit-DB
Huawei Mate 7 - '/dev/hifi_misc' Privilege Escalation
CVE-2015-808824 ene 2016
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RIESGO
abrir
Exploit-DB
NTP - Local Privilege Escalation
CVE-2016-072721 ene 2016
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ub
23RIESGO
abrir
Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (1)
CVE-2016-072819 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (2)
CVE-2016-072819 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DB
CesarFTP 0.99g - XCWD Denial of Service
CVE-2006-296119 ene 2016
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RIESGO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-828218 ene 2016
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
23RIESGO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-828318 ene 2016
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RIESGO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-828418 ene 2016
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RIESGO
abrir
Exploit-DB
mcart.xls Bitrix Module 6.5.2 - SQL Injection
CVE-2015-835615 ene 2016
Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u
23RIESGO
abrir
Exploit-DB
Roundcube Webmail 1.1.3 - Directory Traversal
CVE-2015-877015 ene 2016
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RIESGO
abrir
Exploit-DB
Microsoft Office / COM Object - 'WMALFXGFXDSP.dll' DLL Planting (MS16-007)
CVE-2016-001613 ene 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RIESGO
abrir
Exploit-DB
WhatsUp Gold 16.3 - Remote Code Execution
CVE-2015-826113 ene 2016
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized
23RIESGO
abrir
anteriorpágina 169 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.