Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
DotCMS RCE via Arbitrary File Upload.
CVE-2022-26352CRITICALbajo ataqueransomware03 may 2022
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RIESGO
abrir
Metasploit600
Zyxel Firewall ZTP Unauthenticated Command Injection
CVE-2022-30525CRITICALbajo ataque28 abr 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
Metasploit600
ZoneMinder Language Settings Remote Code Execution
CVE-2022-2980627 abr 2022
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an
30RIESGO
abrir
Metasploit600
Tatsu Wordpress Plugin RCE
CVE-2021-2509425 abr 2022
Tatsu < 3.3.12 - Unauthenticated RCE
60RIESGO
abrir
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34876MEDIUM19 abr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple SQL injection vulnerability at /vicidial/admin.php.
28RIESGO
abrir
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34877MEDIUM19 abr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contains a SQL injection vulnerability at /vicidial/AST_agent_time_sheet.php.
28RIESGO
abrir
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34878MEDIUM19 abr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contain a SQL injection vulnerability at /vicidial/user_stats.php.
28RIESGO
abrir
Metasploit300
VMware vCenter Secrets Dump
CVE-2022-22948MEDIUMbajo ataque15 abr 2022
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act
83RIESGO
abrir
Metasploit600
ManageEngine ADSelfService Plus Custom Script Execution
CVE-2022-28810MEDIUMbajo ataque09 abr 2022
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary
100RIESGO
abrir
Metasploit600
VMware Workspace ONE Access CVE-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware06 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
Metasploit400
VMware Workspace ONE Access CVE-2022-22960
CVE-2022-22960HIGHbajo ataque06 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RIESGO
abrir
Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
CVE-2022-2295706 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities
23RIESGO
abrir
Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
CVE-2022-2295606 abr 2022
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
30RIESGO
abrir
Metasploit600
Dompdf RCE via Malicious Font Caching (CVE-2022-28368)
CVE-2022-2836805 abr 2022
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir
Metasploit400
ALLMediaServer 1.6 SEH Buffer Overflow
CVE-2022-2838101 abr 2022
Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar
30RIESGO
abrir
Metasploit600
WSO2 Arbitrary File Upload to RCE
CVE-2022-29464CRITICALbajo ataqueransomware01 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
Metasploit0
Spring Framework Class property RCE (Spring4Shell)
CVE-2022-22965CRITICALbajo ataque31 mar 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Metasploit600
Spring Cloud Function SpEL Injection
CVE-2022-22963CRITICALbajo ataque29 mar 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
Metasploit600
Wordpress Plugin Elementor Authenticated Upload Remote Code Execution
CVE-2022-1329HIGH29 mar 2022
Elementor Website Builder 3.6.0 - 3.6.2 - Missing Authorization to Remote Code Execution
78RIESGO
abrir
Metasploit500
io_uring Same Type Object Reuse Priv Esc
CVE-2022-104322 mar 2022
A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to cor
18RIESGO
abrir
Metasploit600
Open Web Analytics 1.7.3 - Remote Code Execution (RCE)
CVE-2022-2463718 mar 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
Metasploit600
User Profile Arbitrary Junction Creation Local Privilege Elevation
CVE-2022-26904HIGHbajo ataque17 mar 2022
Windows User Profile Service Elevation of Privilege Vulnerability
66RIESGO
abrir
Metasploit500
Watch Queue Out of Bounds Write
CVE-2022-099514 mar 2022
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This
38RIESGO
abrir
Metasploit300
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
CVE-2022-016914 mar 2022
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RIESGO
abrir
Metasploit600
MyBB Admin Control Code Injection RCE
CVE-2022-24734HIGH09 mar 2022
Remote code execution in mybb
78RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-2498907 mar 2022
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst
30RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-24990CRITICALbajo ataqueransomware07 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
Metasploit300
Wordpress BookingPress bookingpress_front_get_category_services SQLi
CVE-2022-073928 feb 2022
BookingPress < 1.0.11 - Unauthenticated SQL Injection
30RIESGO
abrir
Metasploit600
Webmin File Manager RCE
CVE-2022-0824HIGH26 feb 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir
Metasploit300
GitLab GraphQL API User Enumeration
CVE-2021-4191MEDIUM25 feb 2022
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv
70RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.