Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Ruby on Rails JSON Processor YAML Deserialization Scanner
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RIESGO
abrir
Metasploit300
SSH Username Enumeration
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user d
60RIESGO
abrir
Metasploit300
SSH Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Atlassian Crowd XML Entity Expansion Remote File Access
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef
50RIESGO
abrir
Metasploit300
HTTP Options Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RIESGO
abrir
Metasploit300
X11 No-Auth Scanner
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RIESGO
abrir
Metasploit300
ElasticSearch Snapshot API Directory Traversal
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir
Metasploit300
HTTP Options Detection
IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when sessi
23RIESGO
abrir
Metasploit300
Emby SSRF HTTP Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RIESGO
abrir
Metasploit300
Novell Zenworks Mobile Device Management Admin Credentials
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RIESGO
abrir
Metasploit300
TeamViewer Unquoted URI Handler SMB Redirect
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could
23RIESGO
abrir
Metasploit300
Cross Platform Webkit File Dropper
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RIESGO
abrir
Metasploit300
Nginx Source Code Disclosure/Download
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RIESGO
abrir
Metasploit300
WebEx Remote Command Execution Utility
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RIESGO
abrir
Metasploit300
Netgear SPH200D Directory Traversal Vulnerability
Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET
28RIESGO
abrir
Metasploit300
Samba Symlink Directory Traversal
The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable
50RIESGO
abrir
Metasploit300
TrendMicro ServerProtect File Access
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous
30RIESGO
abrir
Metasploit300
Emby Version Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RIESGO
abrir
Metasploit300
Cambium ePMP 1000 'get_chart' Command Injection (v3.1-3.5-RC7)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir
Metasploit300
Cambium ePMP 1000 'ping' Command Injection (up to v2.5)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir
Metasploit300
Cambium ePMP 1000 Account Password Reset
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the
30RIESGO
abrir
Metasploit300
FortiMail Unauthenticated Login Bypass Scanner
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an
40RIESGO
abrir
Metasploit300
Carlo Gavazzi Energy Meters - Login Brute Force, Extract Info and Dump Plant Database
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Vers
18RIESGO
abrir
Metasploit300
GlassFish Brute Force Utility
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RIESGO
abrir
Metasploit300
Embedthis GoAhead Embedded Web Server Directory Traversal
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remot
23RIESGO
abrir
Metasploit300
Nagios XI Scanner
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
Metasploit300
Nagios XI Scanner
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir
Metasploit300
TrendMicro OfficeScanNT Listener Traversal Arbitrary File Access
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in th
23RIESGO
abrir
Metasploit300
Nagios XI Scanner
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RIESGO
abrir
Metasploit300
Nagios XI Scanner
CVE-2019-15949HIGHbajo ataque
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
anteriorpágina 108 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.