Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
80.409 exploits
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873306 mar 2016
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir
Metasploit0
Apache Jetspeed Arbitrary File Upload
CVE-2016-071006 mar 2016
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873506 mar 2016
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873406 mar 2016
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Metasploit0
Apache Jetspeed Arbitrary File Upload
CVE-2016-070906 mar 2016
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3
60RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873606 mar 2016
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir
Exploit-DB
PHPLib < 7.4 - SQL Injection
CVE-2006-2826webappsphp05 mar 2016
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute
23RIESGO
abrir
Exploit-DB
PHPLib < 7.4 - SQL Injection
CVE-2006-0887webappsphp05 mar 2016
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib d
23RIESGO
abrir
Exploit-DB
Schneider Electric SBO / AS - Multiple Vulnerabilities
CVE-2016-2278remotehardware03 mar 2016
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALbajo ataque03 mar 2016
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
GitHub PoC31
Python script to exploit CVE-2015-4852.
CVE-2015-4852CRITICALbajo ataque03 mar 2016
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
Exploit-DB
DropBearSSHD 2015.71 - Command Injection
CVE-2016-3116remotelinux03 mar 2016
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-c
28RIESGO
abrir
Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
CVE-2006-1128webappsphp02 mar 2016
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows r
23RIESGO
abrir
Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
CVE-2006-1127webappsphp02 mar 2016
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
ATutor 2.2.1 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2016-2555remotephp01 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
Exploit-DBVexDay Proof
Netgear NMS300 ProSafe Network Management System - Arbitrary File Upload (Metasploit)
CVE-2016-1525remotewindows01 mar 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Metasploit600
ATutor 2.2.1 Directory Traversal / Remote Code Execution
CVE-2017-100000201 mar 2016
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course
30RIESGO
abrir
GitHub PoC3
Proof of concept showing how CVE-2016-2098 leads to remote code execution
CVE-2016-209801 mar 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Metasploit600
Ruby on Rails ActionPack Inline ERB Code Execution
CVE-2016-209801 mar 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Metasploit600
ATutor 2.2.1 Directory Traversal / Remote Code Execution
CVE-2016-255501 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
Metasploit600
ATutor 2.2.1 SQL Injection / Remote Code Execution
CVE-2016-255501 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-2526remotewindows26 feb 2016
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets
45RIESGO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-3103remotewindows26 feb 2016
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-2532remotewindows26 feb 2016
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t
35RIESGO
abrir
VulnCheck XDB
local
CVE-2016-0040HIGHbajo ataque26 feb 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
Exploit-DB
phpRPC < 0.7 - Remote Code Execution
CVE-2006-1032webappsphp26 feb 2016
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, ex
23RIESGO
abrir
Exploit-DB
Zimbra 8.0.9 GA - Cross-Site Request Forgery
CVE-2015-6541webappslinux26 feb 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RIESGO
abrir
GitHub PoC45
Exploiting CVE-2016-0040 uninitialized pointer
CVE-2016-0040HIGHbajo ataque26 feb 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
Exploit-DB
Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
CVE-2008-4250CRITICALbajo ataqueremotewindows26 feb 2016
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
GitHub PoC
CVE-2015-0235
CVE-2015-023525 feb 2016
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
anteriorpágina 1021 / 2681siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.