Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Jenkins XStream Groovy classpath Deserialization Vulnerability
CVE-2016-079224 feb 2016
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir
Metasploit600
Primefaces Remote Code Execution Exploit
CVE-2017-1000486CRITICALbajo ataque15 feb 2016
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
Metasploit600
Xymon useradm Command Execution
CVE-2016-205614 feb 2016
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RIESGO
abrir
Metasploit600
Ubiquiti airOS Arbitrary File Upload
CVE-2015-9266CRITICAL13 feb 2016
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RIESGO
abrir
Metasploit600
MS16-016 mrxdav.sys WebDav Local Privilege Escalation
CVE-2016-005109 feb 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
Metasploit600
Advantech WebAccess Dashboard Viewer uploadImageCommon Arbitrary File Upload
CVE-2016-085405 feb 2016
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RIESGO
abrir
Metasploit500
D-Link DSL-2750B OS Command Injection
CVE-2016-20017CRITICALbajo ataque05 feb 2016
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as
100RIESGO
abrir
Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
CVE-2016-152504 feb 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir
Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
CVE-2023-38096CRITICAL04 feb 2016
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability
65RIESGO
abrir
Metasploit300
NETGEAR ProSafe Network Management System 300 Authenticated File Download
CVE-2016-152404 feb 2016
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
CVE-2023-38098HIGH04 feb 2016
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability
41RIESGO
abrir
Metasploit600
lastore-daemon D-Bus Privilege Escalation
CVE-2016-15045HIGH02 feb 2016
Deepin lastore-daemon Privilege Escalation via Unsigned .deb Installation
36RIESGO
abrir
Metasploit600
Oracle ATS Arbitrary File Upload
CVE-2016-049120 ene 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Metasploit600
Oracle ATS Arbitrary File Upload
CVE-2016-049220 ene 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir
Metasploit500
Windows Net-NTLMv2 Reflection DCOM/RPC (Juicy)
CVE-2016-322516 ene 2016
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RIESGO
abrir
Metasploit300
Windows Net-NTLMv2 Reflection DCOM/RPC
CVE-2016-322516 ene 2016
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RIESGO
abrir
Metasploit300
Fortinet SSH Backdoor Scanner
CVE-2016-190909 ene 2016
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0
60RIESGO
abrir
Metasploit300
Juniper SSH Backdoor Scanner
CVE-2015-7755CRITICALbajo ataque20 dic 2015
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir
Metasploit600
D-Link DCS-930L Authenticated Remote Command Execution
CVE-2016-11021HIGHbajo ataque20 dic 2015
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th
98RIESGO
abrir
Metasploit600
TP-Link SC2020n Authenticated Telnet Injection
CVE-2013-257820 dic 2015
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
60RIESGO
abrir
Metasploit600
blueman set_dhcp_handler D-Bus Privilege Escalation
CVE-2015-861218 dic 2015
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir
Metasploit300
Symantec Messaging Gateway 10 Exposure of Stored AD Password Vulnerability
CVE-2016-220317 dic 2015
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RIESGO
abrir
Metasploit300
IBM Tivoli Storage Manager FastBack Server Opcode 0x534 Denial of Service
CVE-2015-193015 dic 2015
Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attacke
18RIESGO
abrir
Metasploit600
Joomla HTTP Header Unauthenticated Remote Code Execution
CVE-2015-856214 dic 2015
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
Metasploit600
ManageEngine Desktop Central 9 FileUploadServlet ConnectionId Vulnerability
CVE-2015-824914 dic 2015
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-3235HIGHbajo ataque08 dic 2015
Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 misha
98RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-004108 dic 2015
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2015-613308 dic 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511
50RIESGO
abrir
Metasploit300
MS15-134 Microsoft Windows Media Center MCL Information Disclosure
CVE-2015-612708 dic 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RIESGO
abrir
Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
CVE-2016-010008 dic 2015
Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges v
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.