Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
pfSense Diag Routes Web Shell Upload
CVE-2021-4128223 feb 2022
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo
40RIESGO
abrir
Metasploit600
Dirty Pipe Local Privilege Escalation via CVE-2022-0847
CVE-2022-0847HIGHbajo ataque20 feb 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Metasploit300
Wordpress MasterStudy Admin Account Creation
CVE-2022-044118 feb 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
Metasploit600
Redis Lua Sandbox Escape
CVE-2022-0543CRITICALbajo ataque18 feb 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
Metasploit600
Sourcegraph gitserver sshCommand RCE
CVE-2022-23642HIGH18 feb 2022
Code Injection in Sourcegraph
78RIESGO
abrir
Metasploit300
Strapi CMS Unauthenticated Password Reset
CVE-2019-1881809 feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Metasploit300
CVE-2022-21999 SpoolFool Privesc
CVE-2022-21999HIGHbajo ataqueransomware08 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit200
Netfilter nft_set_elem_init Heap Overflow Privilege Escalation
CVE-2022-3491807 feb 2022
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff
38RIESGO
abrir
Metasploit600
Docker cgroups Container Escape
CVE-2022-0492HIGHbajo ataque04 feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
Metasploit400
Cisco RV340 SSL VPN Unauthenticated Remote Code Execution
CVE-2022-20699CRITICALbajo ataque02 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
Metasploit600
Zyxel chained RCE using LFI and weak password derivation algorithm
CVE-2023-28770HIGH01 feb 2022
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmwa
48RIESGO
abrir
Metasploit400
Zyxel Unauthenticated LAN Remote Code Execution
CVE-2023-28769CRITICAL01 feb 2022
The buffer overflow vulnerability in the library “libclinkc.so” of the web server “zhttpd” in Zyxel DX5401-B0 firmware v
43RIESGO
abrir
Metasploit300
Microweber CMS v1.2.10 Local File Inclusion (Authenticated)
CVE-2025-34076MEDIUM30 ene 2022
Microweber CMS Authenticated Local File Inclusion via Backup API
28RIESGO
abrir
Metasploit400
vmwgfx Driver File Descriptor Handling Priv Esc
CVE-2022-22942HIGH28 ene 2022
The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to f
36RIESGO
abrir
Metasploit600
Spring Cloud Gateway Remote Code Execution
CVE-2022-22947CRITICALbajo ataque26 ene 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
Metasploit600
GLPI htmLawed php command injection
CVE-2022-35914CRITICALbajo ataque26 ene 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
Metasploit600
Local Privilege Escalation in polkits pkexec
CVE-2021-4034HIGHbajo ataqueransomware25 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Metasploit300
Wordpress RegistrationMagic task_ids Authenticated SQLi
CVE-2021-2486223 ene 2022
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RIESGO
abrir
Metasploit600
Apache Couchdb Erlang RCE
CVE-2022-24706CRITICALbajo ataque21 ene 2022
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
Metasploit600
Oracle Access Manager unauthenticated Remote Code Execution
CVE-2021-35587CRITICALbajo ataque19 ene 2022
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
CVE-2021-4583724 dic 2021
It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send
23RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
CVE-2021-4583924 dic 2021
It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.
18RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.15 or lower - RCE chain from unauthenticated to root via session crafting.
CVE-2021-4584124 dic 2021
In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta
18RIESGO
abrir
Metasploit600
SonicWall SMA 100 Series Authenticated Command Injection
CVE-2021-20039HIGH14 dic 2021
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo
58RIESGO
abrir
Metasploit300
WordPress Modern Events Calendar SQLi Scanner
CVE-2021-2494613 dic 2021
Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection
60RIESGO
abrir
Metasploit600
MobileIron Core Unauthenticated JNDI Injection RCE (via Log4Shell)
CVE-2021-44228CRITICALbajo ataqueransomware12 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit600
Microsoft Exchange Server ChainedSerializationBinder RCE
CVE-2021-42321HIGHbajo ataqueransomware09 dic 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft Exchange Server ChainedSerializationBinder RCE
CVE-2022-23277HIGH09 dic 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit600
UniFi Network Application Unauthenticated JNDI Injection RCE (via Log4Shell)
CVE-2021-44228CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Metasploit300
Log4Shell HTTP Scanner
CVE-2021-45046CRITICALbajo ataqueransomware09 dic 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.