Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
3463 exploits
Metasploit300
Emby SSRF HTTP Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RIESGO
abrir
Metasploit300
ElasticSearch Snapshot API Directory Traversal
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir
Metasploit300
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Veritas Backup Exec Windows Remote File Access
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for
60RIESGO
abrir
Metasploit300
D-Link DIR-615H HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RIESGO
abrir
Metasploit300
MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode U
60RIESGO
abrir
Metasploit300
Xymon Daemon Gather Information
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files
23RIESGO
abrir
Metasploit300
Dell iDRAC Default Login
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
ColdFusion Server Check
CVE-2010-2861CRITICALbajo ataqueransomware
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RIESGO
abrir
Metasploit300
Cambium cnPilot r200/r201 Login Scanner and Config Dump
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration fil
18RIESGO
abrir
Metasploit300
Cisco Network Access Manager Directory Traversal Vulnerability
Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read
23RIESGO
abrir
Metasploit300
Cassandra Web File Read Vulnerability
Cassandra Web 0.5.0 - Remote File Read
36RIESGO
abrir
Metasploit300
Binom3 Web Management Login Scanner, Config and Password File Dump
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for rem
23RIESGO
abrir
Metasploit300
Apache Axis2 Brute Force Utility
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
Metasploit300
Atlassian Crowd XML Entity Expansion Remote File Access
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef
50RIESGO
abrir
Metasploit300
Apache "mod_userdir" User Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RIESGO
abrir
Metasploit300
Apache ActiveMQ Directory Traversal
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP
60RIESGO
abrir
Metasploit300
Apache ActiveMQ JSP Files Source Disclosure
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP
60RIESGO
abrir
Metasploit300
Adobe XML External Entity Injection
CVE-2009-3960MEDIUMbajo ataqueransomware
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RIESGO
abrir
Metasploit300
FTP Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Anonymous FTP Access Detection
Anonymous FTP is enabled.
18RIESGO
abrir
Metasploit300
DNS Amplification Scanner
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive querie
30RIESGO
abrir
Metasploit300
DNS Amplification Scanner
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Serve
30RIESGO
abrir
Metasploit300
PetitPotam
CVE-2021-36942HIGHbajo ataqueransomware
Windows LSA Spoofing Vulnerability
98RIESGO
abrir
Metasploit300
DB2 Authentication Brute Force Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
CouchDB Enum Utility
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
Metasploit300
Apple Airport ACPP Authentication Scanner
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fi
23RIESGO
abrir
Metasploit300
Energizer DUO Trojan Scanner
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RIESGO
abrir
anteriorpágina 115 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.