Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
8460 exploits
VulnCheck XDB
initial-access
CVE-2014-3153HIGHbajo ataque29 may 2016
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-3714HIGHbajo ataque07 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-3714HIGHbajo ataque04 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-754705 abr 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-6271CRITICALbajo ataque30 mar 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque30 mar 2016
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2011-331530 mar 2016
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x befor
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2001-053730 mar 2016
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6278HIGHbajo ataque30 mar 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-822530 mar 2016
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-999530 mar 2016
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-163530 mar 2016
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALbajo ataque30 mar 2016
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-757730 mar 2016
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-18368CRITICALbajo ataque30 mar 2016
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-232130 mar 2016
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-20016CRITICAL30 mar 2016
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-0160HIGHbajo ataque30 mar 2016
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-072815 mar 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-754710 mar 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALbajo ataque03 mar 2016
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-0040HIGHbajo ataque26 feb 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-754721 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-754710 feb 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
VulnCheck XDB
local
CVE-2016-005109 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-856208 feb 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
VulnCheck XDB
local
CVE-2014-4113HIGHbajo ataque07 feb 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2015-157903 feb 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2016-072828 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2016-072823 ene 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
anteriorpágina 279 / 282siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.