Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.043exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
ImageMagick Delegate Arbitrary Command Execution
CVE-2016-3714HIGHbajo ataque03 may 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
Metasploit600
ImageMagick Delegate Arbitrary Command Execution
CVE-2016-797603 may 2016
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams
23RIESGO
abrir
Metasploit600
Allwinner 3.4 Legacy Kernel Local Privilege Escalation
CVE-2016-1022530 abr 2016
The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privil
18RIESGO
abrir
Metasploit500
Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion
CVE-2016-4117HIGHbajo ataque27 abr 2016
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RIESGO
abrir
Metasploit600
Apache Struts Dynamic Method Invocation Remote Code Execution
CVE-2016-308127 abr 2016
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir
Metasploit300
HP Data Protector Encrypted Communication Remote Command Execution
CVE-2016-200418 abr 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir
Metasploit600
pfSense authenticated graph status RCE
CVE-2016-1070918 abr 2016
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RIESGO
abrir
Metasploit600
op5 v7.1.9 Configuration Command Execution
CVE-2025-34115HIGH08 abr 2016
OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php
36RIESGO
abrir
Metasploit600
ExaGrid Known SSH Key and Default Password
CVE-2016-156007 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RIESGO
abrir
Metasploit600
ExaGrid Known SSH Key and Default Password
CVE-2016-156107 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RIESGO
abrir
Metasploit600
Apache CouchDB Arbitrary Command Execution
CVE-2017-1263606 abr 2016
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir
Metasploit600
Apache Continuum Arbitrary Command Execution
CVE-2016-15057CRITICAL06 abr 2016
Apache Continuum: Command injection leading to RCE
43RIESGO
abrir
Metasploit600
Apache CouchDB Arbitrary Command Execution
CVE-2017-1263506 abr 2016
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
Metasploit600
Novell ServiceDesk Authenticated File Upload
CVE-2016-159330 mar 2016
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RIESGO
abrir
Metasploit300
MS16-032 Secondary Logon Handle Privilege Escalation
CVE-2016-0099HIGHbajo ataqueransomware21 mar 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir
Metasploit600
BMC Server Automation RSCD Agent NSH Remote Command Execution
CVE-2016-154216 mar 2016
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir
Metasploit600
BMC Server Automation RSCD Agent NSH Remote Command Execution
CVE-2016-154316 mar 2016
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RIESGO
abrir
Metasploit600
Kaltura Remote PHP Code Execution
CVE-2016-15044CRITICAL15 mar 2016
Kaltura < 11.1.0-2 PHP Object Injection RCE
63RIESGO
abrir
Metasploit600
Exim "perl_startup" Privilege Escalation
CVE-2016-153110 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir
Metasploit0
Apache Jetspeed Arbitrary File Upload
CVE-2016-071006 mar 2016
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RIESGO
abrir
Metasploit0
Apache Jetspeed Arbitrary File Upload
CVE-2016-070906 mar 2016
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3
60RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873506 mar 2016
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873306 mar 2016
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873406 mar 2016
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Metasploit600
Nagios XI Chained Remote Code Execution
CVE-2018-873606 mar 2016
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir
Metasploit600
ATutor 2.2.1 SQL Injection / Remote Code Execution
CVE-2016-255501 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
Metasploit600
ATutor 2.2.1 Directory Traversal / Remote Code Execution
CVE-2017-100000201 mar 2016
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course
30RIESGO
abrir
Metasploit600
Ruby on Rails ActionPack Inline ERB Code Execution
CVE-2016-209801 mar 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Metasploit600
ATutor 2.2.1 Directory Traversal / Remote Code Execution
CVE-2016-255501 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
Metasploit600
Netgear Devices Unauthenticated Remote Command Execution
CVE-2016-1555CRITICALbajo ataque25 feb 2016
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.