Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
KarjaSoft Sami FTP Server 2.0.2 - USER/PASS Remote Buffer Overflow (SEH)
CVE-2006-0441remotewindows01 nov 2016
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Escape 0x100010b Missing Bounds Check
CVE-2016-7391doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - No Bounds Checking in Escape 0x7000194
CVE-2016-7390doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Unchecked User-Provided Pointer in Escape 0x5000027
CVE-2016-8806doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Missing Bounds Check in Escape 0x100009a
CVE-2016-8810doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Stack Buffer Overflow in Escape 0x7000014
CVE-2016-8805doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Stack Buffer Overflow in Escape 0x10000e9
CVE-2016-8807doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Escape Code Leaks Uninitialised ExAllocatePoolWithTag Memory to Userspace
CVE-2016-7386doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - No Bounds Checking in Escape 0x7000170
CVE-2016-8811doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - NvStreamKms 'PsSetCreateProcessNotifyRoutineEx Local Stack Buffer Overflow Callback / Local Privilege Escalation
CVE-2016-8812localwindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before G
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple OS X/iOS - 'mach_ports_register' Multiple Memory Safety s
CVE-2016-4669dosmultiple31 oct 2016
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir
Exploit-DBVexDay Proof
Apple OS X Kernel - IOBluetoothFamily.kext Use-After-Free
CVE-2016-1863dososx31 oct 2016
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local user
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Unchecked Write to User-Provided Pointer in Escape 0x700010d
CVE-2016-7385doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Incorrect Bounds Check in Escape 0x70001b2
CVE-2016-8809doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Rumba 9.3 - ActiveX Stack Buffer Overflow (PoC)
CVE-2016-5228doswindows31 oct 2016
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba
28RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - UVMLiteController ioctl Handling Unchecked Input/Output Lengths Privilege Escalation
CVE-2016-7384localwindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Missing Bounds Check in Escape 0x70000d5
CVE-2016-8808doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple OS X/iOS Kernel - IOSurface Use-After-Free
CVE-2016-4625localosx31 oct 2016
Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspeci
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 - 'task_t' Local Privilege Escalation
CVE-2016-4625localmacos31 oct 2016
Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspeci
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver - Unchecked Write to User-Provided Pointer in Escape 0x600000D
CVE-2016-7387doswindows31 oct 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Exploit-DBVexDay Proof
RealPlayer 18.1.5.705 - '.QCP' Crash (PoC)
CVE-2016-9018doswindows21 oct 2016
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and c
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 (x86/x64) - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (SUID Method)
CVE-2016-5195HIGHbajo ataquelocallinux21 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
CVE-2015-4624remotelinux20 oct 2016
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing RCVT TrueType Instruction Handler Out-of-Bounds Read (MS16-120)
CVE-2016-3209doswindows20 oct 2016
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
CVE-2016-7998webappsphp20 oct 2016
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtLoadKeyEx Read Only Hive Arbitrary File Write Privilege Escalation (MS16-124)
CVE-2016-0079localwindows20 oct 2016
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure Boundary Descriptor Privilege Escalation (MS16-118)
CVE-2016-3387localwindows20 oct 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Function.apply' Information Leak (MS16-119)
CVE-2016-7194doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure DACL Privilege Escalation (MS16-118)
CVE-2016-3388localwindows20 oct 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.map' Heap Overflow (MS16-119)
CVE-2016-7190doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.