Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
CVE-2017-1837126 dic 2016
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passw
23RIESGO
abrir
Metasploit600
TrueOnline / Billion 5200W-T Router Unauthenticated Command Injection
CVE-2017-1837226 dic 2016
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerabili
23RIESGO
abrir
Metasploit600
TrueOnline / ZyXEL P660HN-T v1 Router Unauthenticated Command Injection
CVE-2017-18368CRITICALbajo ataque26 dic 2016
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1003webappsmultiple26 dic 2016
20RIESGO
abrir
Exploit-DBVexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
CVE-2016-10031localwindows26 dic 2016
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RIESGO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALbajo ataquewebappsphp26 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC407
PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container
CVE-2016-10033CRITICALbajo ataque26 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALbajo ataque26 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1004webappsmultiple26 dic 2016
20RIESGO
abrir
Exploit-DB
Sonicwall 8.1.0.2-14sv - 'extensionsettings.cgi' Remote Command Injection (Metasploit)
CVE-2016-9683webappshardware25 dic 2016
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili
28RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALbajo ataquewebappsphp25 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC66
Local privilege escalation through macOS 10.12.1 via CVE-2016-1825 or CVE-2016-7617.
CVE-2016-182525 dic 2016
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RIESGO
abrir
Exploit-DB
Sonicwall 8.1.0.2-14sv - 'viewcert.cgi' Remote Command Injection (Metasploit)
CVE-2016-9684webappshardware24 dic 2016
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili
23RIESGO
abrir
Exploit-DB
Freepbx < 2.11.1.5 - Remote Code Execution
CVE-2014-7235webappsphp23 dic 2016
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9,
35RIESGO
abrir
Exploit-DB
Apache mod_session_crypto - Padding Oracle
CVE-2016-0736webappsmultiple23 dic 2016
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured c
35RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
CVE-2016-10010HIGHlocallinux23 dic 2016
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
CVE-2016-10009HIGHremotelinux23 dic 2016
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
CVE-2016-7637localmacos22 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
CVE-2016-7633dosmacos22 dic 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
CVE-2016-7612dosmultiple22 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Exploit-DB
IBM AIX 6.1/7.1/7.2 - 'Bellmail' Local Privilege Escalation
CVE-2016-8972localaix22 dic 2016
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
CVE-2016-7660dosmultiple22 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
CVE-2016-7617dosmacos22 dic 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - MSHTML CPaste­Command::Convert­Bitmapto­Png Heap Buffer Overflow (MS14-056)
CVE-2014-4138doswindows22 dic 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
CVE-2016-7661dosmultiple22 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
CVE-2016-7621localmacos22 dic 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-10176remotecgi21 dic 2016
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - SIMD.toLocaleString Uninitialized Memory (MS16-145)
CVE-2016-7286doswindows21 dic 2016
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
35RIESGO
abrir
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-10174CRITICALbajo ataqueremotecgi21 dic 2016
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Internationalization Initialization Type Confusion (MS16-144)
CVE-2016-7287doswindows21 dic 2016
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c
35RIESGO
abrir
anteriorpágina 995 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.