Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit300
Active Directory Certificate Services (ADCS) privilege escalation (Certifried)
CVE-2022-26923HIGHbajo ataque
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit300
Netlogon Weak Cryptographic Authentication
CVE-2020-1472MEDIUMbajo ataqueransomware
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit300
Microsoft SRV.SYS WriteAndX Invalid DataOffset
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RIESGO
abrir
Metasploit300
Veritas Backup Exec Server Registry Access
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify
30RIESGO
abrir
Metasploit300
Microsoft SRV.SYS Pipe Transaction No Null
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a de
60RIESGO
abrir
Metasploit300
Microsoft Plug and Play Service Registry Overflow
Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1
50RIESGO
abrir
Metasploit300
WordPress Traversal Directory DoS
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir
Metasploit300
ws - Denial of Service
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
18RIESGO
abrir
Metasploit300
Solaris LPD Arbitrary File Delete
Directory traversal vulnerability in printd line printer daemon (lpd) in Solaris 7 through 10 allows remote attackers to
23RIESGO
abrir
Metasploit300
Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module - Denial of Service
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01;
60RIESGO
abrir
Metasploit300
DoS Exploitation of Allen-Bradley's Legacy Protocol (PCCC)
An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L
23RIESGO
abrir
Metasploit300
Memcached Remote Denial of Service
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin
23RIESGO
abrir
Metasploit300
Samba read_nttrans_ea_list Integer Overflow
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.
50RIESGO
abrir
Metasploit300
Samba lsa_io_trans_names Heap Overflow
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir
Metasploit300
Veritas Backup Exec Windows Remote File Access
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for
60RIESGO
abrir
Metasploit300
Android Browser RCE Through Google Play Store XFO
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RIESGO
abrir
Metasploit300
Samba lsa_io_privilege_set Heap Overflow
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RIESGO
abrir
Metasploit300
RPC DoS targeting *nix rpcbind/libtirpc
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RIESGO
abrir
Metasploit300
Apple Airport ACPP Authentication Scanner
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fi
23RIESGO
abrir
Metasploit300
Energizer DUO Trojan Scanner
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RIESGO
abrir
Metasploit300
CouchDB Enum Utility
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
Metasploit300
DB2 Authentication Brute Force Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
PetitPotam
CVE-2021-36942HIGHbajo ataqueransomware
Windows LSA Spoofing Vulnerability
98RIESGO
abrir
Metasploit300
DNS Amplification Scanner
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Serve
30RIESGO
abrir
Metasploit300
DNS Amplification Scanner
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive querie
30RIESGO
abrir
Metasploit300
Anonymous FTP Access Detection
Anonymous FTP is enabled.
18RIESGO
abrir
Metasploit300
Xymon Daemon Gather Information
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files
23RIESGO
abrir
Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
CVE-2015-1635CRITICALbajo ataque
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Metasploit300
FTP Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir
Metasploit300
Adobe XML External Entity Injection
CVE-2009-3960MEDIUMbajo ataqueransomware
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RIESGO
abrir
anteriorpágina 113 / 116siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.