Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
GitHub PoC4
Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header
CVE-2015-856208 ene 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting
CVE-2014-8380webappsphp07 ene 2017
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir
Metasploit400
Debian/Ubuntu ntfs-3g Local Privilege Escalation
CVE-2017-0358HIGH05 ene 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir
Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
CVE-2016-7200HIGHbajo ataqueremotewindows05 ene 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
CVE-2016-7201HIGHbajo ataqueremotewindows05 ene 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
Exploit-DBVexDay Proof
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
CVE-2016-6283webappsjsp04 ene 2017
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DB
Firejail < 0.9.44.4 / < 0.9.38.8 LTS - Local Sandbox Escape
CVE-2017-5180locallinux04 ene 2017
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-7201HIGHbajo ataque04 ene 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
GitHub PoC140
Proof-of-Concept exploit for Edge bugs (CVE-2016-7200 & CVE-2016-7201)
CVE-2016-7200HIGHbajo ataque04 ene 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-7200HIGHbajo ataque04 ene 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir
GitHub PoC
Script to take advantage of CVE-2010-3847
CVE-2010-384702 ene 2017
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-10033CRITICALbajo ataquewebappsphp02 ene 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-10045webappsphp02 ene 2017
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-10034webappsphp02 ene 2017
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-363602 ene 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-10074webappsphp02 ene 2017
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RIESGO
abrir
Exploit-DB
Zend Framework / zend-mail < 2.4.11 - Remote Code Execution
CVE-2016-10034webappsphp30 dic 2016
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - get_user/put_user (Metasploit)
CVE-2013-6282HIGHbajo ataquelocalandroid29 dic 2016
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir
GitHub PoC8
Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.
CVE-2016-10033CRITICALbajo ataque29 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALbajo ataquewebappsphp29 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
SwiftMailer < 5.4.5-DEV - Remote Code Execution
CVE-2016-10074webappsphp28 dic 2016
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RIESGO
abrir
Exploit-DB
SapLPD 7.40 - Denial of Service
CVE-2016-10079doswindows28 dic 2016
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long
23RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
CVE-2016-10033CRITICALbajo ataquewebappsphp27 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
CVE-2016-10045webappsphp27 dic 2016
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RIESGO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1004webappsmultiple26 dic 2016
20RIESGO
abrir
Exploit-DBVexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
CVE-2016-10031localwindows26 dic 2016
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RIESGO
abrir
GitHub PoC407
PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container
CVE-2016-10033CRITICALbajo ataque26 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC2
k0keoyo/CVE-2012-0003_eXP
CVE-2012-0003HIGH26 dic 2016
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RIESGO
abrir
Exploit-DBVexDay Proof
Shutter 0.93.1 - Code Execution
CVE-2016-10081locallinux26 dic 2016
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RIESGO
abrir
Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
CVE-2017-1837026 dic 2016
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in t
23RIESGO
abrir
anteriorpágina 994 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.