Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit300
Syncovery For Linux Web-GUI Session Token Brute-Forcer
CVE-2022-3653606 sep 2022
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
18RIESGO
abrir
Metasploit600
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
CVE-2022-3653406 sep 2022
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c
30RIESGO
abrir
Metasploit500
pfSense plugin pfBlockerNG unauthenticated RCE as root
CVE-2022-31814CRITICAL05 sep 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
Metasploit600
Symmetricom SyncServer Unauthenticated Remote Command Execution
CVE-2022-40022CRITICAL31 ago 2022
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
85RIESGO
abrir
Metasploit400
WatchGuard XTM Firebox Unauthenticated Remote Command Execution
CVE-2022-26318CRITICALbajo ataque29 ago 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir
Metasploit600
Bitbucket Git Command Injection
CVE-2022-36804HIGHbajo ataque24 ago 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Metasploit600
FLIR AX8 unauthenticated RCE
CVE-2022-3706119 ago 2022
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This
60RIESGO
abrir
Metasploit300
Rancher Authenticated API Credential Exposure
CVE-2021-36782CRITICAL18 ago 2022
Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io object
63RIESGO
abrir
Metasploit500
VMware Workspace ONE Access CVE-2022-31660
CVE-2022-3166002 ago 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A m
18RIESGO
abrir
Metasploit600
Softing Secure Integration Server v1.22 Remote Code Execution
CVE-2022-1373HIGH27 jul 2022
Softing Secure Integration Server Relative Path Traversal
41RIESGO
abrir
Metasploit600
Softing Secure Integration Server v1.22 Remote Code Execution
CVE-2022-2334HIGH27 jul 2022
Softing Secure Integration Server Uncontrolled Search Path Element
41RIESGO
abrir
Metasploit600
Webmin Package Updates RCE
CVE-2022-3644626 jul 2022
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
Metasploit600
Apache Spark Unauthenticated Command Injection RCE
CVE-2022-33891HIGHbajo ataque18 jul 2022
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
Metasploit600
Roxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCE
CVE-2022-31137CRITICAL06 jul 2022
Unauthenticated Remote Code Execution in Roxy-WI
85RIESGO
abrir
Metasploit600
ManageEngine ADAudit Plus CVE-2022-28219
CVE-2022-2821929 jun 2022
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote
60RIESGO
abrir
Metasploit600
Advantech iView NetworkServlet Command Injection
CVE-2022-2143CRITICAL28 jun 2022
Advantech iView
75RIESGO
abrir
Metasploit600
TAR Path Traversal in Zimbra (CVE-2022-41352)
CVE-2022-41352CRITICALbajo ataque28 jun 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir
Metasploit600
UnRAR Path Traversal in Zimbra (CVE-2022-30333)
CVE-2022-30333HIGHbajo ataqueransomware28 jun 2022
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RIESGO
abrir
Metasploit600
UnRAR Path Traversal (CVE-2022-30333)
CVE-2022-30333HIGHbajo ataqueransomware28 jun 2022
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) o
100RIESGO
abrir
Metasploit600
Zoho Password Manager Pro XML-RPC Java Deserialization
CVE-2022-35405CRITICALbajo ataque24 jun 2022
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RIESGO
abrir
Metasploit600
Cisco ASA-X with FirePOWER Services Authenticated Command Injection
CVE-2022-20828MEDIUM22 jun 2022
Cisco FirePOWER Software for ASA FirePOWER Module Command Injection Vulnerability
40RIESGO
abrir
Metasploit600
Zyxel Firewall SUID Binary Privilege Escalation
CVE-2022-30526HIGH14 jun 2022
A privilege escalation vulnerability was identified in the CLI command of Zyxel USG FLEX 100(W) firmware versions 4.50 t
36RIESGO
abrir
Metasploit600
Atlassian Confluence Namespace OGNL Injection
CVE-2022-26134CRITICALbajo ataqueransomware02 jun 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
Metasploit600
Microsoft Office Word MSDTJS
CVE-2022-30190HIGHbajo ataqueransomware29 may 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
SuiteCRM authenticated SQL injection in export functionality
CVE-2023-5350MEDIUM24 may 2022
SQL Injection in salesagility/suitecrm
28RIESGO
abrir
Metasploit600
Gitea Git Fetch Remote Code Execution
CVE-2022-3078116 may 2022
Gitea before 1.16.7 does not escape git fetch remote.
60RIESGO
abrir
Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
CVE-2022-37042CRITICALbajo ataqueransomware10 may 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RIESGO
abrir
Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
CVE-2022-27925HIGHbajo ataqueransomware10 may 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
Metasploit300
Icingaweb Directory Traversal in Static Library File Requests
CVE-2022-24716HIGH09 may 2022
Path traversal in Icinga Web 2
78RIESGO
abrir
Metasploit600
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVE-2022-1388CRITICALbajo ataqueransomware04 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.