Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Firefox nsSMILTimeContainer::NotifyTimeChange() RCE
CVE-2016-9079HIGHbajo ataque30 nov 2016
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
Metasploit600
Jenkins CLI HTTP Java Deserialization Vulnerability
CVE-2016-929916 nov 2016
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RIESGO
abrir
Metasploit300
Zyxel/Eir D1000 DSL Modem NewNTPServer Command Injection Over TR-064
CVE-2016-1037207 nov 2016
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary c
40RIESGO
abrir
Metasploit600
Dlink DIR Routers Unauthenticated HNAP Login Stack Buffer Overflow
CVE-2016-656307 nov 2016
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RIESGO
abrir
Metasploit400
WinaXe 7.7 FTP Client Remote Buffer Overflow
CVE-2025-34107HIGH03 nov 2016
WinaXe 7.7 FTP Client Remote Buffer Overflow
36RIESGO
abrir
Metasploit600
Bassmaster Batch Arbitrary JavaScript Injection Remote Code Execution
CVE-2014-720501 nov 2016
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir
Metasploit300
Joomla Account Creation and Privilege Escalation
CVE-2016-887025 oct 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
Metasploit300
Joomla Account Creation and Privilege Escalation
CVE-2016-886925 oct 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir
Metasploit600
Ruby on Rails Dynamic Render File Upload Remote Code Execution
CVE-2016-0752HIGHbajo ataque16 oct 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
Metasploit600
PowerShellEmpire Arbitrary File Upload (Skywalker)
CVE-2024-6127CRITICAL15 oct 2016
BC Security Empire Path Traversal RCE
68RIESGO
abrir
Metasploit300
Cisco Firepower Management Console 6.0 Post Auth Report Download Directory Traversal
CVE-2016-643510 oct 2016
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RIESGO
abrir
Metasploit600
Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability
CVE-2016-643310 oct 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir
Metasploit0
Apache Tomcat on RedHat Based Systems Insecure Temp Config Privilege Escalation
CVE-2016-542510 oct 2016
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RIESGO
abrir
Metasploit600
Disk Pulse Enterprise Login Buffer Overflow
CVE-2025-34108HIGH03 oct 2016
Disk Pulse Enterprise 9.0.34 Login Stack Buffer Overflow
36RIESGO
abrir
Metasploit0
Apache Tomcat on Ubuntu Log Init Privilege Escalation
CVE-2016-124030 sep 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
Metasploit300
Cisco IKE Information Disclosure
CVE-2016-6415HIGHbajo ataque29 sep 2016
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir
Metasploit300
BIND TSIG Query Denial of Service
CVE-2016-277627 sep 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir
Metasploit600
MagniComp SysInfo mcsiwrapper Privilege Escalation
CVE-2017-651623 sep 2016
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir
Metasploit600
BuilderEngine Arbitrary File Upload Vulnerability and execution
CVE-2025-34100CRITICAL18 sep 2016
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RIESGO
abrir
Metasploit500
Grandstream GXV31XX 'settimezone' Unauthenticated Command Execution
CVE-2019-1065501 sep 2016
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.
23RIESGO
abrir
Metasploit400
Safari Webkit JIT Exploit for iOS 7.1.2
CVE-2016-466925 ago 2016
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir
Metasploit400
Safari Webkit JIT Exploit for iOS 7.1.2
CVE-2018-416225 ago 2016
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
30RIESGO
abrir
Metasploit0
WebKit not_number defineProperties UAF
CVE-2016-4655MEDIUMbajo ataque25 ago 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
Metasploit0
WebKit not_number defineProperties UAF
CVE-2016-4657HIGHbajo ataque25 ago 2016
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
Metasploit0
WebKit not_number defineProperties UAF
CVE-2016-4656HIGHbajo ataque25 ago 2016
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir
Metasploit400
AF_PACKET chocobo_root Privilege Escalation
CVE-2016-865512 ago 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir
Metasploit300
ColoradoFTP Server 1.3 Build 8 Directory Traversal Information Disclosure
CVE-2025-34110CRITICAL11 ago 2016
ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
63RIESGO
abrir
Metasploit300
Zabbix toggle_ids SQL Injection
CVE-2016-1013411 ago 2016
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQ
40RIESGO
abrir
Metasploit300
Internet Explorer Iframe Sandbox File Name Disclosure Vulnerability
CVE-2016-332109 ago 2016
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the f
30RIESGO
abrir
Metasploit600
Trend Micro Smart Protection Server Exec Remote Code Injection
CVE-2016-626708 ago 2016
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330
30RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.