Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
Metasploit300
Check Point Security Gateway Arbitrary File Read
CVE-2024-24919HIGHbajo ataqueransomware
Information disclosure
100RIESGO
abrir
Metasploit300
MSSQL Login Utility
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RIESGO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service Remote File Access
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RIESGO
abrir
Metasploit300
CrushFTP AWS4-HMAC Authentication Bypass
35RIESGO
abrir
Metasploit300
EasyCafe Server Remote File Access
EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
36RIESGO
abrir
Metasploit300
Multiple DVR Manufacturers Configuration Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RIESGO
abrir
Metasploit300
Dahua DVR Auth Bypass Scanner
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
60RIESGO
abrir
Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
CVE-2024-4040CRITICALbajo ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
Metasploit300
cups-browsed Information Disclosure
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
Metasploit300
DNS Record Scanner and Enumerator
A DNS server allows zone transfers.
30RIESGO
abrir
Metasploit300
Lotus Domino Password Hash Collector
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RIESGO
abrir
Metasploit300
Novell ZENworks Asset Management 7.5 Configuration Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RIESGO
abrir
Metasploit300
Novell ZENworks Asset Management 7.5 Remote File Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RIESGO
abrir
Metasploit300
Firefox PDF.js Browser File Theft
CVE-2015-4495HIGHbajo ataque
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir
Metasploit300
WordPress Subscribe Comments File Read Vulnerability
Subscribe to Comments <= 2.1.2 - Local File Includion
36RIESGO
abrir
Metasploit300
FortiOS Path Traversal Credential Gatherer
CVE-2018-13379CRITICALbajo ataqueransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Metasploit300
WordPress Simple Backup File Read Vulnerability
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
36RIESGO
abrir
Metasploit300
WordPress NextGEN Gallery Directory Read Vulnerability
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
23RIESGO
abrir
Metasploit300
WordPress Mobile Edition File Read Vulnerability
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary
30RIESGO
abrir
Metasploit300
WordPress Mobile Pack Information Disclosure Vulnerability
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post
23RIESGO
abrir
Metasploit300
WordPress GI-Media Library Plugin Directory Traversal Vulnerability
GI-Media Library < 3.0 - Directory Traversal
36RIESGO
abrir
Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir
Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Wordpress Pingback Locator
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct
23RIESGO
abrir
Metasploit300
WordPress Brute Force and User Enumeration Utility
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RIESGO
abrir
Metasploit300
WordPress XMLRPC GHOST Vulnerability Scanner
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
Metasploit300
HTTP WebDAV Internal IP Scanner
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RIESGO
abrir
Metasploit300
ManageEngine ADAudit Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RIESGO
abrir
Metasploit300
ManageEngine DataSecurity Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RIESGO
abrir
anteriorpágina 108 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.