Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-5309dosmultiple21 sep 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
CVE-2016-3357doswindows21 sep 2016
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
CVE-2016-7083doswindows19 sep 2016
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
CVE-2016-7084doswindows19 sep 2016
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RIESGO
abrir
Exploit-DBVexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
CVE-2016-6253localnetbsd_x8615 sep 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RIESGO
abrir
Exploit-DBVexDay Proof
Cherry Music 0.35.1 - Arbitrary File Disclosure
CVE-2015-8309webappsphp13 sep 2016
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - libutils UTF16 to UTF8 Conversion Heap Buffer Overflow
CVE-2016-3861remoteandroid08 sep 2016
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Transform.colorTranform Getter Infomation Leak
CVE-2016-4232dosmultiple08 sep 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Method Calls Use-After-Free
CVE-2016-4231dosmultiple08 sep 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
CVE-2016-4264webappsmultiple07 sep 2016
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attack
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MovieClip Transform Getter Use-After-Free
CVE-2016-4230dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free When Returning Rectangle
CVE-2016-4228dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Stage.align Setter Use-After-Free
CVE-2016-4226dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Selection.setFocus Use-After-Free
CVE-2016-4227dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - BitmapData.copyPixels Use-After-Free
CVE-2016-4229dosmultiple29 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Eye of Gnome 3.10.2 - GMarkup Out of Bounds Write
CVE-2016-6855doslinux23 ago 2016
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib befor
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
CVE-2016-6896webappsphp22 ago 2016
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
CVE-2016-6897webappsphp22 ago 2016
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir
Exploit-DBVexDay Proof
Ocomon 2.0 - SQL Injection
CVE-2005-4664webappsphp22 ago 2016
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - GDI+ DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)
CVE-2016-3301doswindows17 ago 2016
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - GDI+ ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)
CVE-2016-3303doswindows17 ago 2016
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - GDI+ EMR_EXTTEXTOUTA / EMR_POLYTEXTOUTA Heap Buffer Overflow (MS16-097)
CVE-2016-3304doswindows17 ago 2016
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - MSHTML!CMultiReadStreamLifetimeManager::ReleaseThreadStateInternal Read AV
CVE-2016-3288doswindows16 ago 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet E
35RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
CVE-2016-4315webappsjsp16 ago 2016
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
CVE-2016-4311webappsjsp16 ago 2016
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
CVE-2016-3316dosmultiple16 ago 2016
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
CVE-2016-4316webappsjsp16 ago 2016
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
CVE-2016-4312webappsjsp16 ago 2016
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RIESGO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Local File Inclusion
CVE-2016-4314webappsjsp16 ago 2016
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Word 2007/2010/2013/2016 - Out-of-Bounds Read Code Execution (MS16-099)
CVE-2016-3313localwindows10 ago 2016
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote at
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.