Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Sophos Web Appliance 4.2.1.3 - block/unblock Remote Command Injection (Metasploit)
CVE-2016-9553webappsphp12 dic 2016
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its w
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - MSHTML CDisp­Node::Insert­Sibling­Node Use-After-Free (MS13-037) (1)
CVE-2013-1309doswindows09 dic 2016
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - MSHTML CDisp­Node::Insert­Sibling­Node Use-After-Free (MS13-037) (2)
CVE-2013-1306doswindows09 dic 2016
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr
35RIESGO
abrir
Exploit-DBVexDay Proof
Netgear R7000 - Command Injection
CVE-2016-6277HIGHbajo ataquewebappscgi07 dic 2016
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - JSON.parse Info Leak
CVE-2016-7241doswindows06 dic 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - CDoc::Execute­Script­Uri Use-After-Free (MS13-009)
CVE-2013-0019doswindows06 dic 2016
Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary co
35RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Inter-Process munmap with User-Controlled Size in android.graphics.Bitmap
CVE-2016-6707remoteandroid06 dic 2016
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 coul
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.4.0 (Ubuntu 14.04/16.04 x86-64) - 'AF_PACKET' Race Condition Privilege Escalation
CVE-2016-8655locallinux_x86-6406 dic 2016
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - 'jscript9' Java­Script­Stack­Walker Memory Corruption (MS15-056)
CVE-2015-1730remotewindows06 dic 2016
Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory cor
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - CMarkup::Ensure­Delete­CFState Use-After-Free (MS15-125)
CVE-2015-6168doswindows06 dic 2016
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a
35RIESGO
abrir
Exploit-DBVexDay Proof
Apache CouchDB 2.0.0 - Local Privilege Escalation
CVE-2016-8742localwindows05 dic 2016
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Event Viewer 1.0 - XML External Entity Injection
CVE-2019-0948MEDIUMlocalwindows05 dic 2016
Windows Event Viewer Information Disclosure Vulnerability
38RIESGO
abrir
Exploit-DBVexDay Proof
Alcatel Lucent Omnivista 8770 - Remote Code Execution
CVE-2016-9796remotewindows04 dic 2016
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP pro
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9314webappshardware28 nov 2016
Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtua
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - MSHTML 'SRun­Pointer::Span­Qualifier/Run­Type' Out-Of-Bounds Read (MS15-009)
CVE-2015-0050doswindows28 nov 2016
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memo
35RIESGO
abrir
Exploit-DBVexDay Proof
Red Hat JBoss EAP - Deserialization of Untrusted Data
CVE-2016-7065webappsjava28 nov 2016
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to caus
28RIESGO
abrir
Exploit-DBVexDay Proof
NTP 4.2.8p3 - Denial of Service
CVE-2015-7855doslinux28 nov 2016
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' 'PTRACE_POKEDATA' Race Condition Privilege Escalation (/etc/passwd Method)
CVE-2016-5195HIGHbajo ataquelocallinux28 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9269webappshardware28 nov 2016
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appli
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9316webappshardware28 nov 2016
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8/9/10/11 - MSHTML 'DOMImplementation' Type Confusion (MS16-009)
CVE-2016-0063doswindows28 nov 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 10 - MSHTML 'CEdit­Adorner::Detach' Use-After-Free (MS13-047)
CVE-2013-3120doswindows28 nov 2016
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9315webappshardware28 nov 2016
Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan We
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)
CVE-2016-5195HIGHbajo ataquelocallinux27 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
GNU Wget < 1.18 - Access List Bypass / Race Condition
CVE-2016-7098remotemultiple24 nov 2016
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Crestron AM-100 - Multiple Vulnerabilities
CVE-2016-5639remotehardware22 nov 2016
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RIESGO
abrir
Exploit-DBVexDay Proof
Huawei UTPS - Unquoted Service Path Privilege Escalation
CVE-2016-8769localwindows22 nov 2016
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the
23RIESGO
abrir
Exploit-DBVexDay Proof
NTP 4.2.8p8 - Denial of Service
CVE-2016-7434doslinux21 nov 2016
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - jscript 'Reg­Exp­Base::FBad­Header' Use-After-Free (MS15-018)
CVE-2015-2482doswindows21 nov 2016
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 an
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Scripting Engine - Memory Corruption (MS16-129)
CVE-2016-7202doswindows21 nov 2016
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.