Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Registry Hive Loading Negative RtlMoveMemory Size in nt!CmpCheckValueList (MS16-124)
CVE-2016-0070doswindows20 oct 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serve
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.join' Infomation Leak (MS16-119)
CVE-2016-7189doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site,
35RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.1/3.1.2 - File Enumeration / Path Traversal
CVE-2016-7982webappsphp20 oct 2016
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to en
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtLoadKeyEx Read Only Hive Arbitrary File Write Privilege Escalation (MS16-124)
CVE-2016-0079localwindows20 oct 2016
The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application
23RIESGO
abrir
Exploit-DBVexDay Proof
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
CVE-2016-7998webappsphp20 oct 2016
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing win32k!sbit_Embolden / win32k!ttfdCloseFontContext Use-After-Free (MS16-120)
CVE-2016-7182doswindows20 oct 2016
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; W
35RIESGO
abrir
Exploit-DBVexDay Proof
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
CVE-2015-4624remotelinux20 oct 2016
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)
CVE-2016-5195HIGHbajo ataquelocallinux19 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DeviceApi CMApi User Hive Impersonation Privilege Escalation (MS16-124)
CVE-2016-0073localwindows18 oct 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
CVE-2011-1249localwindows_x8618 oct 2016
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DFS Client Driver Arbitrary Drive Mapping Privilege Escalation (MS16-123)
CVE-2016-7185localwindows18 oct 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DeviceApi CMApi PiCMOpenDeviceKey Arbitrary Registry Key Write Privilege Escalation (MS16-124)
CVE-2016-0075localwindows18 oct 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails - Dynamic Render File Upload / Remote Code Execution (Metasploit)
CVE-2016-0752HIGHbajo ataqueremotemultiple17 oct 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Diagnostics Hub - DLL Load Privilege Escalation (MS16-125)
CVE-2016-7188localwindows17 oct 2016
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Webex Player T29.10 - '.ARF' Out-of-Bounds Memory Corruption
CVE-2016-1415doswindows12 oct 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Binder Generic ASLR Leak
CVE-2016-6689dosandroid12 oct 2016
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Webex Player T29.10 - '.WRF' Use-After-Free Memory Corruption
CVE-2016-1464doswindows12 oct 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 23.0.0.162 - '.SWF' ConstantPool Critical Memory Corruption
CVE-2016-4273dosmultiple12 oct 2016
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637
28RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'gpsOneXtra' Data Files Denial of Service
CVE-2016-5348dosandroid11 oct 2016
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.1 - 'Recvmmsg' Local Privilege Escalation (Metasploit)
CVE-2014-0038locallinux11 oct 2016
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
CVE-2016-6433webappscgi05 oct 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 8/7/6 (Debian-Based Distros) - Local Privilege Escalation
CVE-2016-1240locallinux03 oct 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
Exploit-DBVexDay Proof
Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit)
CVE-2015-3864remoteandroid27 sep 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
CVE-2016-4997locallinux_x8627 sep 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
CVE-2016-3371localwindows26 sep 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
CVE-2016-3373localwindows26 sep 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Crash When Freeing Memory After AVC decoding
CVE-2016-4275dosmultiple23 sep 2016
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RIESGO
abrir
Exploit-DBVexDay Proof
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
CVE-2016-5725doswindows22 sep 2016
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
CVE-2016-3237localwindows22 sep 2016
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
CVE-2016-3357doswindows21 sep 2016
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.