Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
3463 exploits
Metasploit300
NTP Clock Variables Disclosure
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
ws - Denial of Service
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
18RIESGO
abrir
Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
CVE-2024-4040CRITICALbajo ataque
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir
Metasploit300
Oracle RDBMS Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
HTTP Options Detection
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when sessi
23RIESGO
abrir
Metasploit300
HTTP Options Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RIESGO
abrir
Metasploit300
PcAnywhere Login Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Portmapper Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
WordPress Traversal Directory DoS
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir
Metasploit300
Novell Zenworks Mobile Device Management Admin Credentials
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RIESGO
abrir
Metasploit300
ua-parser-js npm module ReDoS
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o
18RIESGO
abrir
Metasploit300
Tautulli v2.1.9 - Shutdown Denial of Service
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous a
23RIESGO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Metasploit300
Nginx Source Code Disclosure/Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RIESGO
abrir
Metasploit300
Netgear SPH200D Directory Traversal Vulnerability
Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET
28RIESGO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RIESGO
abrir
Metasploit300
SSH Username Enumeration
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RIESGO
abrir
Metasploit300
SSH Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVE-2015-1635CRITICALbajo ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Metasploit300
SSH Version Scanner
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2
28RIESGO
abrir
Metasploit300
Nagios XI Scanner
CVE-2019-15949HIGHbajo ataque
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
Metasploit300
Nagios XI Scanner
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au
23RIESGO
abrir
Metasploit300
DNS Record Scanner and Enumerator
A DNS server allows zone transfers.
30RIESGO
abrir
Metasploit300
Firefox PDF.js Browser File Theft
CVE-2015-4495HIGHbajo ataque
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RIESGO
abrir
Metasploit300
FortiOS Path Traversal Credential Gatherer
CVE-2018-13379CRITICALbajo ataqueransomware
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Metasploit300
Nagios XI Scanner
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir
Metasploit300
Nagios XI Scanner
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
Metasploit300
FreeBSD Remote NFS RPC Request Denial of Service
nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demo
50RIESGO
abrir
Metasploit300
ISC DHCP Zero Length ClientID Denial of Service Module
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit)
60RIESGO
abrir
anteriorpágina 112 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.