Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
CVE-2016-7998webappsphp20 oct 2016
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Array.map' Heap Overflow (MS16-119)
CVE-2016-7190doswindows20 oct 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing win32k!sbit_Embolden / win32k!ttfdCloseFontContext Use-After-Free (MS16-120)
CVE-2016-7182doswindows20 oct 2016
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; W
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Registry Hive Loading Negative RtlMoveMemory Size in nt!CmpCheckValueList (MS16-124)
CVE-2016-0070doswindows20 oct 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serve
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'win32k.sys' TTF Processing RCVT TrueType Instruction Handler Out-of-Bounds Read (MS16-120)
CVE-2016-3209doswindows20 oct 2016
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure DACL Privilege Escalation (MS16-118)
CVE-2016-3388localwindows20 oct 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RIESGO
abrir
Exploit-DBVexDay Proof
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
CVE-2015-4624remotelinux20 oct 2016
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)
CVE-2016-5195HIGHbajo ataquelocallinux19 oct 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DeviceApi CMApi PiCMOpenDeviceKey Arbitrary Registry Key Write Privilege Escalation (MS16-124)
CVE-2016-0075localwindows18 oct 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DFS Client Driver Arbitrary Drive Mapping Privilege Escalation (MS16-123)
CVE-2016-7185localwindows18 oct 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DeviceApi CMApi User Hive Impersonation Privilege Escalation (MS16-124)
CVE-2016-0073localwindows18 oct 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
CVE-2011-1249localwindows_x8618 oct 2016
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Diagnostics Hub - DLL Load Privilege Escalation (MS16-125)
CVE-2016-7188localwindows17 oct 2016
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RIESGO
abrir
Exploit-DBVexDay Proof
Ruby on Rails - Dynamic Render File Upload / Remote Code Execution (Metasploit)
CVE-2016-0752HIGHbajo ataqueremotemultiple17 oct 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Webex Player T29.10 - '.ARF' Out-of-Bounds Memory Corruption
CVE-2016-1415doswindows12 oct 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 23.0.0.162 - '.SWF' ConstantPool Critical Memory Corruption
CVE-2016-4273dosmultiple12 oct 2016
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Webex Player T29.10 - '.WRF' Use-After-Free Memory Corruption
CVE-2016-1464doswindows12 oct 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Binder Generic ASLR Leak
CVE-2016-6689dosandroid12 oct 2016
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 3.13.1 - 'Recvmmsg' Local Privilege Escalation (Metasploit)
CVE-2014-0038locallinux11 oct 2016
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - 'gpsOneXtra' Data Files Denial of Service
CVE-2016-5348dosandroid11 oct 2016
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
CVE-2016-6433webappscgi05 oct 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 8/7/6 (Debian-Based Distros) - Local Privilege Escalation
CVE-2016-1240locallinux03 oct 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
CVE-2016-4997locallinux_x8627 sep 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RIESGO
abrir
Exploit-DBVexDay Proof
Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit)
CVE-2015-3864remoteandroid27 sep 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
CVE-2016-3373localwindows26 sep 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
CVE-2016-3371localwindows26 sep 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Crash When Freeing Memory After AVC decoding
CVE-2016-4275dosmultiple23 sep 2016
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RIESGO
abrir
Exploit-DBVexDay Proof
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
CVE-2016-5725doswindows22 sep 2016
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
CVE-2016-3237localwindows22 sep 2016
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RIESGO
abrir
Exploit-DBVexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-5310dosmultiple21 sep 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.