Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Stack Corruption (MS16-026)
CVE-2016-0120doswindows14 mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir
Exploit-DBVexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-7562webappsphp14 mar 2016
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Pool-Based Buffer Overflow (MS16-026)
CVE-2016-0121doswindows14 mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir
Exploit-DBVexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-7564webappsphp14 mar 2016
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Exim < 4.86.2 - Local Privilege Escalation
CVE-2016-1531locallinux10 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.84-3 - Local Privilege Escalation
CVE-2016-1531locallinux09 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Digital Editions 4.5.0 - '.pdf' Critical Memory Corruption
CVE-2016-0954doswindows09 mar 2016
Adobe Digital Editions before 4.5.1 allows attackers to execute arbitrary code or cause a denial of service (memory corr
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-3135doslinux09 mar 2016
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-3134doslinux09 mar 2016
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local us
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution
CVE-2016-2539webappsphp07 mar 2016
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Avast! - Authenticode Parsing Memory Corruption
CVE-2016-3986doswindows07 mar 2016
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 2.2.1 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2016-2555remotephp01 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
Exploit-DBVexDay Proof
Netgear NMS300 ProSafe Network Management System - Arbitrary File Upload (Metasploit)
CVE-2016-1525remotewindows01 mar 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Exploit-DBVexDay Proof
libxml2 - xmlDictAddString Heap Buffer Overread
CVE-2016-1839doslinux24 feb 2016
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS befo
23RIESGO
abrir
Exploit-DBVexDay Proof
libxml2 - xmlParserPrintFileContextInternal Heap Buffer Overread
CVE-2016-1838doslinux24 feb 2016
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Server Administrator 8.2 - (Authenticated) Directory Traversal
CVE-2016-4004webappswindows23 feb 2016
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SimpleButton Creation Type Confusion
CVE-2015-8644dosmultiple19 feb 2016
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Sound.loadPCMFromByteArray Dangling Pointer
CVE-2016-0984HIGHbajo ataquedosmultiple17 feb 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
83RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - LoadVars.decode Use-After-Free
CVE-2016-0974dosmultiple17 feb 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - H264 File Stack Corruption
CVE-2016-0967dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - textfield Constructor Type Confusion
CVE-2016-0985dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Image Read
CVE-2016-0965dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Heap Overflow
CVE-2016-0971dosmultiple17 feb 2016
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - BitmapData.drawWithQuality Heap Overflow
CVE-2016-0964dosmultiple17 feb 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RIESGO
abrir
Exploit-DBVexDay Proof
glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)
CVE-2015-7547doslinux16 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Kerberos Security Feature Bypass (MS16-014)
CVE-2016-0049localwindows15 feb 2016
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 SP1 (x86) - 'WebDAV' Local Privilege Escalation (MS16-016) (1)
CVE-2016-0051localwindows_x8610 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Exploit-DBVexDay Proof
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
CVE-2016-0956webappsmultiple10 feb 2016
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.iff' Parsing Memory Corruption
CVE-2016-0953doswindows09 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
CVE-2016-0952doswindows09 feb 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.