Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
13.743 exploits
GitHub PoC1
Redis RCE through Lua Sandbox Escape vulnerability
CVE-2022-0543CRITICALbajo ataque05 sep 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
GitHub PoC23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
CVE-2021-34527HIGHbajo ataqueransomware05 sep 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC22
CVE-2022-2586: Linux kernel nft_object UAF
CVE-2022-2586MEDIUMbajo ataque03 sep 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RIESGO
abrir
GitHub PoC1
0xrobiul/CVE-2018-15473
CVE-2018-15473MEDIUM03 sep 2022
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
Zabbix-SAML-Bypass: CVE-2022-23131
CVE-2022-23131CRITICALbajo ataque02 sep 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC4
Powertek PDU身份绕过
CVE-2022-33174CRITICAL02 sep 2022
Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas
68RIESGO
abrir
GitHub PoC5
Win10 20H2 LPE for CVE-2021-31956
CVE-2021-31956HIGHbajo ataque02 sep 2022
Windows NTFS Elevation of Privilege Vulnerability
76RIESGO
abrir
GitHub PoC
75ACOL/CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque01 sep 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC6
OpenSSL
CVE-2022-1292CRITICAL01 sep 2022
The c_rehash script allows command injection
70RIESGO
abrir
GitHub PoC
shavchen/CVE-2022-26138
CVE-2022-26138CRITICALbajo ataque01 sep 2022
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th
100RIESGO
abrir
GitHub PoC2
CVE-2022-24124 exploit
CVE-2022-2412431 ago 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RIESGO
abrir
GitHub PoC
Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)
CVE-2022-0847HIGHbajo ataque31 ago 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC84
CVE-2020-1472 C++
CVE-2020-1472MEDIUMbajo ataqueransomware31 ago 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC5
Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3
CVE-2022-2463730 ago 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
GitHub PoC3
Oracle Weblogic RCE - CVE-2022-2109
CVE-2021-2109HIGH30 ago 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir
GitHub PoC
CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891729 ago 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC
Adobe Acrobat Reader UAF vulnerability Exploit code
CVE-2020-9715HIGHbajo ataque29 ago 2022
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.3
83RIESGO
abrir
GitHub PoC1
Apache Spark RCE - CVE-2022-33891
CVE-2022-33891HIGHbajo ataque29 ago 2022
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
GitHub PoC
CVE-2017-7269 implemented in C#
CVE-2017-7269CRITICALbajo ataque29 ago 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC
CVE-2017-7269 implemented in python3
CVE-2017-7269CRITICALbajo ataque28 ago 2022
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC2
CVE-2022-0492-Container-Escape
CVE-2022-0492HIGHbajo ataque27 ago 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
GitHub PoC
A Docker image vulnerable to CVE-2020-7246.
CVE-2020-724627 ago 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
GitHub PoC9
Search for BTC coins on earlier versions of Bitcoin Core with critical vulnerability OpenSSL 0.9.8 CVE-2008-0166
CVE-2008-016626 ago 2022
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir
GitHub PoC1
CVE-2022-26134 web payload
CVE-2022-26134CRITICALbajo ataqueransomware26 ago 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC5
Python Script to exploit Zimbra Auth Bypass + RCE (CVE-2022-27925)
CVE-2022-27925HIGHbajo ataqueransomware26 ago 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
GitHub PoC18
Oracle WebLogic CVE-2022-21371
CVE-2022-21371HIGH25 ago 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RIESGO
abrir
GitHub PoC19
Zimbra CVE-2022-37042 Nuclei weaponized template
CVE-2022-37042CRITICALbajo ataqueransomware25 ago 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RIESGO
abrir
GitHub PoC
Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware25 ago 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
nvchungkma/CVE-2021-40444-Microsoft-Office-Word-Remote-Code-Execution-
CVE-2021-40444HIGHbajo ataqueransomware24 ago 2022
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC9
SiJiDo/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque23 ago 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
anteriorpágina 299 / 459siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.