Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Metasploit500
Cisco WebEx Chrome Extension RCE (CVE-2017-3823)
CVE-2017-382321 ene 2017
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Conta
23RIESGO
abrir
Metasploit300
Advantech WebAccess 8.1 Post Authentication Credential Collector
CVE-2016-581021 ene 2017
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive
23RIESGO
abrir
Exploit-DB
Joomla! < 3.6.4 - Admin Takeover
CVE-2016-9838webappsphp20 ene 2017
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RIESGO
abrir
Exploit-DB
Joomla! < 2.5.2 - Admin Creation
CVE-2012-1563webappsphp20 ene 2017
Joomla! before 2.5.3 allows Admin Account Creation.
23RIESGO
abrir
GitHub PoC271
CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow
CVE-2016-5195HIGHbajo ataque20 ene 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC1
cve-2009-3103
CVE-2009-310317 ene 2017
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir
Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
CVE-2016-7617localmacos16 ene 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir
GitHub PoC3
Android APK Based On Public Information Using DirtyCOW CVE-2016-5195 Exploit
CVE-2016-5195HIGHbajo ataque16 ene 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
CVE-2016-1825localmacos16 ene 2017
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-5195HIGHbajo ataque15 ene 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-639815 ene 2017
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user
30RIESGO
abrir
GitHub PoC
sribaba/android-CVE-2016-5195
CVE-2016-5195HIGHbajo ataque15 ene 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-7255HIGHbajo ataqueransomware13 ene 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
Exploit-DB
Mozilla Firefox < 50.1.0 - Use-After-Free
CVE-2016-9899doswindows13 ene 2017
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
CVE-2016-6433remotelinux13 ene 2017
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir
GitHub PoC3
heh3/CVE-2016-7255
CVE-2016-7255HIGHbajo ataqueransomware13 ene 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6339webappshardware12 ene 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6338webappshardware12 ene 2017
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6340webappshardware12 ene 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
CVE-2017-2930dosmultiple11 ene 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
CVE-2017-2930dosmultiple11 ene 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RIESGO
abrir
Exploit-DB
Apple OS X Yosemite - 'flow_divert-heap-overflow' Kernel Panic
CVE-2016-1827dososx10 ene 2017
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
GitHub PoC4
Proof-of-concept exploit for CVE-2016-1827 on OS X Yosemite.
CVE-2016-182710 ene 2017
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-1427CRITICALbajo ataque09 ene 2017
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC32
Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container
CVE-2015-1427CRITICALbajo ataque09 ene 2017
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
Exploit-DB
Ansible 2.1.4/2.2.1 - Command Execution
CVE-2016-9587MEDIUMremotelinux09 ene 2017
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent fr
38RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)
CVE-2016-7255HIGHbajo ataqueransomwarelocalwindows08 ene 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856208 ene 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC4
Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header
CVE-2015-856208 ene 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC151
ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container
CVE-2015-330608 ene 2017
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
anteriorpágina 993 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.