Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
4202 exploits
Nucleimedium
Lyrion Music Server <= 9.2.0 - Cross-Site Scripting
Lyrion Music Server 9.2.0 Reflected XSS via server.log
28RIESGO
abrir
Nucleihigh
Langflow <= 1.8.4 - Path Traversal to RCE via File Upload
Langflow - Path Traversal Arbitrary File Write via upload_user_file
68RIESGO
abrir
Nucleimedium
Pure-FTPd ≤ 1.0.18 - DoS via Connection Limit Exhaustion
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceed
18RIESGO
abrir
Nucleimedium
ProFTPD 1.2.x - Username Enumeration via Timing Attack
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which al
50RIESGO
abrir
Nucleimedium
Titan FTP ≤ 3.21 - Heap Overflow via Long Commands
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) vi
38RIESGO
abrir
Nucleihigh
Distccd v1 - Remote Code Execution
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RIESGO
abrir
Nucleimedium
FileZilla Server < 0.9.6 - DoS via MS-DOS Device Names
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename cont
18RIESGO
abrir
Nucleimedium
FileZilla Server < 0.9.6 - DoS via MODE Z Infinite Loop
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of se
18RIESGO
abrir
Nucleimedium
FileZilla FTP Server 2.2.22 - Buffer Overflow
Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and po
18RIESGO
abrir
Nucleimedium
FileZilla Server < 0.9.22 - DoS via Wildcard Commands
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RIESGO
abrir
Nucleicritical
Titan FTP Server 6.03 and 6.0.5.549 - Heap Overflow via Long Commands
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RIESGO
abrir
Nucleicritical
Titan FTP Server 6.05 DELE Command - Heap Overflow
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a lo
38RIESGO
abrir
Nucleimedium
FileZilla Server < 0.9.31 - SSL/TLS Packet Overflow DoS
Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified v
18RIESGO
abrir
Nucleihigh
ProFTPD < 1.3.3c - Directory Traversal via mod_site_misc
Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authentic
18RIESGO
abrir
Nucleimedium
vsftpd < 2.3.3 - DoS
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RIESGO
abrir
Nucleicritical
VSFTPD 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Nucleilow
Pure-FTPd ≤ 1.0.22 - Directory Traversal
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise
18RIESGO
abrir
Nucleimedium
Titan FTP Server < 10.40 Move Function - Directory Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Nucleimedium
Titan FTP Server Search Function < 10.40 - User Enumeration
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Nucleimedium
Titan FTP Server < 10.40 - User Properties Traversal
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attacke
38RIESGO
abrir
Nucleimedium
vsftpd <= 3.0.2 - Access Restriction Bypass
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown
18RIESGO
abrir
Nucleicritical
ProFTPd - Remote Code Execution
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
Nucleicritical
HP Data Protector - Arbitrary Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir
Nucleicritical
Oracle WebLogic Server Java Object Deserialization - Remote Code Execution
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12
40RIESGO
abrir
Nucleicritical
Cisco IOS 12.2(55)SE11 - Remote Code Execution
CVE-2017-3881CRITICALbajo ataque
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
Nucleicritical
Apache Log4j Server - Deserialization Command Execution
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events
40RIESGO
abrir
Nucleicritical
Oracle WebLogic Server Deserialization - Remote Code Execution
CVE-2018-2628CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Nucleicritical
Oracle WebLogic Server - Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir
Nucleihigh
ProFTPD < 1.3.6b - Remote Unauthenticated DoS
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handl
23RIESGO
abrir
Nucleihigh
Pure-FTPd < 1.0.50 - DoS via Resource Exhaustion
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
18RIESGO
abrir
anteriorpágina 112 / 141siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.