Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
macOS Dirty Cow Arbitrary File Write Local Privilege Escalation
CVE-2022-46689HIGH17 dic 2022
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RIESGO
abrir
Metasploit600
Cacti 1.2.22 unauthenticated command injection
CVE-2022-46169CRITICALbajo ataque05 dic 2022
Unauthenticated Command Injection
100RIESGO
abrir
Metasploit300
Mirage firewall for QubesOS 0.8.0-0.8.3 Denial of Service (DoS) Exploit
CVE-2022-46770HIGH04 dic 2022
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s
61RIESGO
abrir
Metasploit0
WhatsUp Gold Credentials Dump
CVE-2022-2984522 nov 2022
In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke
18RIESGO
abrir
Metasploit0
WhatsUp Gold Credentials Dump
CVE-2022-2984822 nov 2022
In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke
18RIESGO
abrir
Metasploit600
VSCode ipynb Remote Development RCE
CVE-2022-41034HIGH22 nov 2022
Visual Studio Code Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit0
WhatsUp Gold Credentials Dump
CVE-2022-2984622 nov 2022
In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obt
18RIESGO
abrir
Metasploit0
WhatsUp Gold Credentials Dump
CVE-2022-2984722 nov 2022
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to i
30RIESGO
abrir
Metasploit600
Bitbucket Environment Variable RCE
CVE-2022-43781CRITICAL16 nov 2022
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
65RIESGO
abrir
Metasploit600
F5 BIG-IP iControl CSRF File Write SOAP API
CVE-2022-41622HIGH16 nov 2022
iControl SOAP vulnerability
58RIESGO
abrir
Metasploit600
F5 BIG-IP iControl Authenticated RCE via RPM Creator
CVE-2022-41800HIGH16 nov 2022
Appliance mode iControl REST vulnerability
68RIESGO
abrir
Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
CVE-2022-38120MEDIUM10 nov 2022
POWERCOM CO., LTD. UPSMON PRO - Path Traversal
28RIESGO
abrir
Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
CVE-2022-38121MEDIUM10 nov 2022
POWERCOM CO., LTD. UPSMON PRO - Insufficiently Protected Credentials
28RIESGO
abrir
Metasploit400
Lenovo Diagnostics Driver IOCTL memmove
CVE-2022-3699HIGH09 nov 2022
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RIESGO
abrir
Metasploit600
Acronis Cyber Protect/Backup remote code execution
CVE-2022-3405CRITICAL08 nov 2022
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
43RIESGO
abrir
Metasploit600
Authenticated RCE in Splunk (SimpleXML dashboard PDF generation)
CVE-2022-43571HIGH02 nov 2022
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
41RIESGO
abrir
Metasploit600
Clinic's Patient Management System 1.0 - Unauthenticated RCE
CVE-2022-40471CRITICAL31 oct 2022
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p
68RIESGO
abrir
Metasploit600
VMware NSX Manager XStream unauthenticated RCE
CVE-2021-39144HIGHbajo ataque25 oct 2022
XStream is vulnerable to a Remote Command Execution attack
100RIESGO
abrir
Metasploit600
SolarWinds Information Service (SWIS) .NET Deserialization From AMQP RCE
CVE-2022-38108HIGH19 oct 2022
SolarWinds Platform Deserialization of Untrusted Data
48RIESGO
abrir
Metasploit600
Apache Commons Text RCE
CVE-2022-4288913 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
Metasploit600
Zimbra sudo + postfix privilege escalation
CVE-2022-3569HIGH13 oct 2022
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalat
36RIESGO
abrir
Metasploit600
Fortinet FortiOS, FortiProxy, and FortiSwitchManager authentication bypass.
CVE-2022-40684CRITICALbajo ataqueransomware10 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
Metasploit600
GitLab GitHub Repo Import Deserialization RCE
CVE-2022-2992CRITICAL06 oct 2022
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows
85RIESGO
abrir
Metasploit600
Oracle E-Business Suite (EBS) Unauthenticated Arbitrary File Upload
CVE-2022-21587CRITICALbajo ataqueransomware01 oct 2022
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyNotShell RCE
CVE-2022-41082HIGHbajo ataqueransomware28 sep 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft Exchange ProxyNotShell RCE
CVE-2022-41040HIGHbajo ataqueransomware28 sep 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
mySCADA MyPRO Authenticated Command Injection (CVE-2023-28384)
CVE-2023-28384HIGH22 sep 2022
CVE-2023-28384
48RIESGO
abrir
Metasploit300
Mobile Mouse RCE
CVE-2023-31902CRITICAL20 sep 2022
RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).
63RIESGO
abrir
Metasploit300
Remote Control Collection RCE
CVE-2022-4978CRITICAL20 sep 2022
Steppschuh Remote Control Server 3.1.1.12 Unauthenticated RCE
63RIESGO
abrir
Metasploit500
Ubuntu Enlightenment Mount Priv Esc
CVE-2022-37706HIGH13 sep 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.