Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Ruby on Rails XML Processor YAML Deserialization Scanner
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
Metasploit300
FortiOS Path Traversal Credential Gatherer
CVE-2018-13379CRITICALbajo ataqueransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Metasploit300
Firefox PDF.js Browser File Theft
CVE-2015-4495HIGHbajo ataque
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir
Metasploit300
DNS Record Scanner and Enumerator
A DNS server allows zone transfers.
30RIESGO
abrir
Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
CVE-2024-4040CRITICALbajo ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
Metasploit300
CrushFTP AWS4-HMAC Authentication Bypass
35RIESGO
abrir
Metasploit300
Check Point Security Gateway Arbitrary File Read
CVE-2024-24919HIGHbajo ataqueransomware
Information disclosure
100RIESGO
abrir
Metasploit300
Apache Reverse Proxy Bypass Vulnerability Scanner
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RIESGO
abrir
Metasploit300
RIPS Scanner Directory Traversal
RIPS Scanner v0.54 Path Traversal
36RIESGO
abrir
Metasploit300
Apache Tomcat User Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RIESGO
abrir
Metasploit300
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
Metasploit300
Apache Rave User Information Disclosure
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Android Open Source Platform (AOSP) Browser UXSS
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RIESGO
abrir
Metasploit300
Android Content Provider File Disclosure
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// UR
43RIESGO
abrir
Metasploit300
Adobe ColdFusion Unauthenticated Arbitrary File Read
CVE-2023-26360HIGHbajo ataque
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RIESGO
abrir
Metasploit300
Acronis Cyber Protect/Backup machine info disclosure
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
43RIESGO
abrir
Metasploit300
Acronis Cyber Protect/Backup machine info disclosure
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Prot
43RIESGO
abrir
Metasploit300
BADPDF Malicious PDF Creator
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
40RIESGO
abrir
Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RIESGO
abrir
Metasploit300
TP-Link Wireless Lite N Access Point Directory Traversal Vulnerability
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13
50RIESGO
abrir
Metasploit300
HTTP Cross-Site Tracing Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RIESGO
abrir
Metasploit300
WANGKONGBAO CNS-1000 and 1100 UTM Directory Traversal
Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attacke
50RIESGO
abrir
Metasploit300
HTTP WebDAV Internal IP Scanner
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RIESGO
abrir
Metasploit300
WordPress XMLRPC GHOST Vulnerability Scanner
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
anteriorpágina 109 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.