Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Logsign Remote Command Injection
CVE-2024-5721HIGH26 feb 2017
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability
36RIESGO
abrir
Metasploit600
Netgear DGN2200 dnslookup.cgi Command Injection
CVE-2017-6334HIGHbajo ataque25 feb 2017
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir
Metasploit300
Kodi 17.0 Local File Inclusion Vulnerability
CVE-2017-598212 feb 2017
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files v
40RIESGO
abrir
Metasploit600
Piwik Superuser Plugin Upload
CVE-2025-34104CRITICAL05 feb 2017
Piwik Authenticated RCE via Custom Plugin Upload
43RIESGO
abrir
Metasploit300
Postfixadmin Protected Alias Deletion Vulnerability
CVE-2017-593003 feb 2017
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected al
23RIESGO
abrir
Metasploit300
WordPress REST API Content Injection
CVE-2017-100100001 feb 2017
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in Wor
40RIESGO
abrir
Metasploit600
AlienVault OSSIM/USM Remote Code Execution
CVE-2016-858231 ene 2017
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RIESGO
abrir
Metasploit600
Haraka SMTP Command Injection
CVE-2016-100028226 ene 2017
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlie
23RIESGO
abrir
Metasploit600
Oracle Weblogic Server Deserialization RCE - RMI UnicastRef
CVE-2017-324825 ene 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
Metasploit300
Geutebrueck GCore - GCoreServer.exe Buffer Overflow RCE
CVE-2017-1151724 ene 2017
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir
Metasploit500
Cisco WebEx Chrome Extension RCE (CVE-2017-3823)
CVE-2017-382321 ene 2017
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Conta
23RIESGO
abrir
Metasploit300
Advantech WebAccess 8.1 Post Authentication Credential Collector
CVE-2016-581021 ene 2017
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive
23RIESGO
abrir
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-639815 ene 2017
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user
30RIESGO
abrir
Metasploit400
Debian/Ubuntu ntfs-3g Local Privilege Escalation
CVE-2017-0358HIGH05 ene 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir
Metasploit0
PHPMailer Sendmail Argument Injection
CVE-2016-10033CRITICALbajo ataque26 dic 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
CVE-2017-1837126 dic 2016
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passw
23RIESGO
abrir
Metasploit0
PHPMailer Sendmail Argument Injection
CVE-2016-1004526 dic 2016
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RIESGO
abrir
Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
CVE-2017-1837026 dic 2016
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in t
23RIESGO
abrir
Metasploit600
TrueOnline / Billion 5200W-T Router Unauthenticated Command Injection
CVE-2017-1836926 dic 2016
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote
30RIESGO
abrir
Metasploit600
TrueOnline / Billion 5200W-T Router Unauthenticated Command Injection
CVE-2017-1837226 dic 2016
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerabili
23RIESGO
abrir
Metasploit600
TrueOnline / ZyXEL P660HN-T v1 Router Unauthenticated Command Injection
CVE-2017-18368CRITICALbajo ataque26 dic 2016
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir
Metasploit600
VMware VDP Known SSH Key
CVE-2016-745620 dic 2016
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which mak
30RIESGO
abrir
Metasploit300
NETGEAR WNR2000v5 Administrator Password Recovery
CVE-2016-1017520 dic 2016
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi
50RIESGO
abrir
Metasploit600
NETGEAR WNR2000v5 (Un)authenticated hidden_lang_avi Stack Buffer Overflow
CVE-2016-10174CRITICALbajo ataque20 dic 2016
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RIESGO
abrir
Metasploit300
NETGEAR WNR2000v5 Administrator Password Recovery
CVE-2016-1017620 dic 2016
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RIESGO
abrir
Metasploit600
Western Digital MyCloud unauthenticated command injection
CVE-2018-1715314 dic 2016
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulne
40RIESGO
abrir
Metasploit600
Western Digital MyCloud unauthenticated command injection
CVE-2016-1010814 dic 2016
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytic
40RIESGO
abrir
Metasploit600
Netgear R7000 and R6400 cgi-bin Command Injection
CVE-2016-6277HIGHbajo ataque06 dic 2016
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Metasploit600
DiskBoss Enterprise GET Buffer Overflow
CVE-2025-34105CRITICAL05 dic 2016
DiskBoss Enterprise Stack-Based Buffer Overflow RCE
43RIESGO
abrir
Metasploit600
DiskSavvy Enterprise GET Buffer Overflow
CVE-2017-618701 dic 2016
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary c
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.