Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
SSH Username Enumeration
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations
50RIESGO
abrir
Metasploit300
SNMP Community Login Scanner
An SNMP community name is the default (e.g. public), null, or missing.
33RIESGO
abrir
Metasploit300
SNMP Community Login Scanner
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RIESGO
abrir
Metasploit300
SNMP Community Login Scanner
An SNMP community name is guessable.
23RIESGO
abrir
Metasploit300
SNMP Enumeration Module
An SNMP community name is the default (e.g. public), null, or missing.
33RIESGO
abrir
Metasploit300
SNMP Enumeration Module
An account on a router, firewall, or other network device has a default, null, blank, or missing password.
18RIESGO
abrir
Metasploit300
WinRM Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
SNMP Enumeration Module
An SNMP community name is guessable.
23RIESGO
abrir
Metasploit300
VNC Authentication None Detection
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers t
60RIESGO
abrir
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community string
18RIESGO
abrir
Metasploit300
Cambium ePMP 1000 SNMP Enumeration
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration
18RIESGO
abrir
Metasploit300
Cambium cnPilot r200/r201 SNMP Enumeration
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access
18RIESGO
abrir
Metasploit300
Linux DoS Xen 4.2.0 2012-5525
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service
18RIESGO
abrir
Metasploit300
Check For and Prep the Pyrotechnic Devices (Airbags, Battery Clamps, etc.)
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to th
18RIESGO
abrir
Metasploit300
Haserl Arbitrary File Reader
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to
18RIESGO
abrir
Metasploit300
WordPress Traversal Directory DoS
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir
Metasploit300
ua-parser-js npm module ReDoS
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o
18RIESGO
abrir
Metasploit300
WordPress Simple Backup File Read Vulnerability
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
36RIESGO
abrir
Metasploit300
WordPress Subscribe Comments File Read Vulnerability
Subscribe to Comments <= 2.1.2 - Local File Includion
36RIESGO
abrir
Metasploit300
Tautulli v2.1.9 - Shutdown Denial of Service
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous a
23RIESGO
abrir
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVE-2015-1635CRITICALbajo ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Metasploit300
Novell ZENworks Asset Management 7.5 Remote File Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RIESGO
abrir
Metasploit300
Novell ZENworks Asset Management 7.5 Configuration Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RIESGO
abrir
Metasploit300
Lotus Domino Password Hash Collector
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RIESGO
abrir
Metasploit300
cups-browsed Information Disclosure
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir
Metasploit300
Dahua DVR Auth Bypass Scanner
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
60RIESGO
abrir
Metasploit300
Multiple DVR Manufacturers Configuration Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RIESGO
abrir
Metasploit300
EasyCafe Server Remote File Access
EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
36RIESGO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service Remote File Access
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RIESGO
abrir
Metasploit300
MSSQL Login Utility
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RIESGO
abrir
anteriorpágina 109 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.