Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
3463 exploits
Metasploit300
Novell eDirectory eMBox Unauthenticated File Access
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on clien
50RIESGO
abrir
Metasploit300
Novell eDirectory DHOST Predictable Session Cookie
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote att
50RIESGO
abrir
Metasploit300
SNMP Enumeration Module
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RIESGO
abrir
Metasploit300
Active Directory Certificate Services (ADCS) privilege escalation (Certifried)
CVE-2022-26923HIGHbajo ataque
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit300
SNMP Enumeration Module
An SNMP community name is the default (e.g. public), null, or missing.
33RIESGO
abrir
Metasploit300
Check For and Prep the Pyrotechnic Devices (Airbags, Battery Clamps, etc.)
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to th
18RIESGO
abrir
Metasploit300
Linux DoS Xen 4.2.0 2012-5525
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service
18RIESGO
abrir
Metasploit300
Netlogon Weak Cryptographic Authentication
CVE-2020-1472MEDIUMbajo ataqueransomware
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit300
Haserl Arbitrary File Reader
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to
18RIESGO
abrir
Metasploit300
Veritas Backup Exec Server Registry Access
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify
30RIESGO
abrir
Metasploit300
Veritas Backup Exec Windows Remote File Access
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for
60RIESGO
abrir
Metasploit300
SNMP Enumeration Module
An SNMP community name is guessable.
23RIESGO
abrir
Metasploit300
Diagnostics Agent in Solution Manager, stores unencrypted credentials for Solution Manager server
Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So
18RIESGO
abrir
Metasploit300
Bypass the macOS TCC Framework
CVE-2020-9934MEDIUMbajo ataque
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue
78RIESGO
abrir
Metasploit300
SNMP Community Login Scanner
An SNMP community name is guessable.
23RIESGO
abrir
Metasploit300
Android Browser RCE Through Google Play Store XFO
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RIESGO
abrir
Metasploit300
Windows Gather Forensics Duqu Registry Check
CVE-2011-3402HIGHbajo ataque
Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Wind
88RIESGO
abrir
Metasploit300
SNMP Community Login Scanner
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RIESGO
abrir
Metasploit300
Solaris LPD Arbitrary File Delete
Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to
23RIESGO
abrir
Metasploit300
Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module - Denial of Service
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RIESGO
abrir
Metasploit300
Microsoft Plug and Play Service Registry Overflow
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1
50RIESGO
abrir
Metasploit300
Microsoft SRV.SYS Pipe Transaction No Null
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a de
60RIESGO
abrir
Metasploit300
Microsoft SRV.SYS WriteAndX Invalid DataOffset
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RIESGO
abrir
Metasploit300
Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir
Metasploit300
Microsoft SRV2.SYS SMB2 Logoff Remote Kernel NULL Pointer Dereference
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir
Metasploit300
Microsoft Windows 7 / Server 2008 R2 SMB Client Infinite Loop
Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB serv
50RIESGO
abrir
Metasploit300
Microsoft Windows SRV.SYS SrvSmbQueryFsInformation Pool Overflow DoS
The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2
60RIESGO
abrir
Metasploit300
Microsoft Windows Browser Pool DoS
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in
50RIESGO
abrir
Metasploit300
DoS Exploitation of Allen-Bradley's Legacy Protocol (PCCC)
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L
23RIESGO
abrir
Metasploit300
BADPDF Malicious PDF Creator
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
40RIESGO
abrir
anteriorpágina 110 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.