Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
3463 exploits
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration
18RIESGO
abrir
Metasploit300
Cambium cnPilot r200/r201 SNMP Enumeration
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access
18RIESGO
abrir
Metasploit300
Arris DG950A Cable Modem Wifi Enumeration
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote atta
23RIESGO
abrir
Metasploit300
SMTP Open Relay Detection
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
23RIESGO
abrir
Metasploit300
SMTP User Enumeration Utility
15RIESGO
abrir
Metasploit300
Samba _netr_ServerPasswordSet Uninitialized Credential State
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1
60RIESGO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0144HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0148HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0143HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0146HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0145HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
MS17-010 SMB RCE Detection
CVE-2017-0147HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit300
SMB Login Check Scanner
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RIESGO
abrir
Metasploit300
SMB Group Policy Preference Saved Passwords Enumeration
CVE-2014-1812HIGHbajo ataqueransomware
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
98RIESGO
abrir
Metasploit300
Microsoft Windows Authenticated Logged In Users Enumeration
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Sielco Sistemi Winlog Remote File Access
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA bef
43RIESGO
abrir
Metasploit300
Moxa UDP Device Discovery
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RIESGO
abrir
Metasploit300
Indusoft WebStudio NTWebServer Remote File Access
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote att
30RIESGO
abrir
Metasploit300
SAP /sap/bc/soap/rfc SOAP Service RFC_SYSTEM_INFO Function Sensitive Information Gathering
SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an
23RIESGO
abrir
Metasploit300
SAP URL Scanner
CVE-2010-0738MEDIUMbajo ataqueransomware
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir
Metasploit300
SAP Host Agent Information Disclosure
The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitiv
23RIESGO
abrir
Metasploit300
rsh Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
rsh Authentication Scanner
The rsh/rlogin service is running.
23RIESGO
abrir
Metasploit300
rlogin Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
rlogin Authentication Scanner
The rsh/rlogin service is running.
23RIESGO
abrir
Metasploit300
rexec Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
rexec Authentication Scanner
The rsh/rlogin service is running.
23RIESGO
abrir
Metasploit300
MS12-020 Microsoft Remote Desktop Checker
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RIESGO
abrir
Metasploit300
PostgreSQL Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
PostgreSQL Database Name Command Line Flag Injection
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows re
30RIESGO
abrir
anteriorpágina 111 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.