Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
3463 exploits
Metasploit300
NTP Clock Variables Disclosure
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir ↗Metasploit300
ws - Denial of Service
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
18RIESGO
abrir ↗Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗Metasploit300
Oracle RDBMS Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
HTTP Options Detection
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when sessi
23RIESGO
abrir ↗Metasploit300
HTTP Options Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RIESGO
abrir ↗Metasploit300
PcAnywhere Login Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
Portmapper Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir ↗Metasploit300
WordPress Traversal Directory DoS
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir ↗Metasploit300
Novell Zenworks Mobile Device Management Admin Credentials
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RIESGO
abrir ↗Metasploit300
ua-parser-js npm module ReDoS
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o
18RIESGO
abrir ↗Metasploit300
Tautulli v2.1.9 - Shutdown Denial of Service
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous a
23RIESGO
abrir ↗Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Metasploit300
Nginx Source Code Disclosure/Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RIESGO
abrir ↗Metasploit300
Netgear SPH200D Directory Traversal Vulnerability
Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET
28RIESGO
abrir ↗Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RIESGO
abrir ↗Metasploit300
SSH Username Enumeration
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir ↗Metasploit300
SSH Username Enumeration
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RIESGO
abrir ↗Metasploit300
SSH Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Metasploit300
SSH Version Scanner
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2
28RIESGO
abrir ↗Metasploit300
Nagios XI Scanner
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir ↗Metasploit300
Nagios XI Scanner
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RIESGO
abrir ↗Metasploit300
Firefox PDF.js Browser File Theft
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RIESGO
abrir ↗Metasploit300
FortiOS Path Traversal Credential Gatherer
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir ↗Metasploit300
Nagios XI Scanner
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir ↗Metasploit300
Nagios XI Scanner
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir ↗Metasploit300
FreeBSD Remote NFS RPC Request Denial of Service
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demo
50RIESGO
abrir ↗Metasploit300
ISC DHCP Zero Length ClientID Denial of Service Module
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.