Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
13.812 exploits
GitHub PoC12
Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalation
CVE-2021-3560HIGHbajo ataque02 may 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware02 may 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC60
yuanLink/CVE-2022-26809
CVE-2022-26809CRITICAL01 may 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
CVE-2021-3560HIGHbajo ataque30 abr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
CVE-2021-44228 Log4j Summary
CVE-2021-44228CRITICALbajo ataqueransomware30 abr 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque29 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
CVE-2021-3560HIGHbajo ataque29 abr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC2
CVE-2022-29464 POC exploit
CVE-2022-29464CRITICALbajo ataqueransomware29 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
CVE-2018-1942229 abr 2022
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
GitHub PoC13
A tool for extracting, modifying, and crafting ASDM binary packages (CVE-2022-20829)
CVE-2022-20829CRITICAL28 abr 2022
Cisco Adaptive Security Device Manager and Adaptive Security Appliance Software Client-side Arbitrary Code Execution Vulnerability
48RIESGO
abrir
GitHub PoC
RedLeavesChilde/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware28 abr 2022
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC3
for kernel 3.18.x
CVE-2019-2215HIGHbajo ataque28 abr 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC4
khidottrivi/CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque27 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
OS X 10.11.6 LPE PoC for CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMbajo ataque27 abr 2022
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
GitHub PoC14
CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具
CVE-2021-41773HIGHbajo ataqueransomware27 abr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
lowkey0808/cve-2022-29464
CVE-2022-29464CRITICALbajo ataqueransomware26 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC1
CVE-2021-43857(gerapy命令执行)
CVE-2021-43857CRITICAL26 abr 2022
Gerapy may contain remote code execution vulnerability
60RIESGO
abrir
GitHub PoC
PoC for Dirty COW (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque26 abr 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
CVE-2022-23046 phpIPAM 1.4.4
CVE-2022-2304626 abr 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RIESGO
abrir
GitHub PoC8
Page Table Manipulation -- CVE-2018-19321
CVE-2018-19321HIGHbajo ataqueransomware26 abr 2022
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, X
71RIESGO
abrir
GitHub PoC210
CVE-2022-22947 注入Godzilla内存马
CVE-2022-22947CRITICALbajo ataque26 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC1
Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x
CVE-2021-3064CRITICAL26 abr 2022
PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
53RIESGO
abrir
GitHub PoC
This is the story of CVE-2022-0847, a vulnerability in the Linux kernel since 5.8 which allows overwriting data in arbitrary read-only files. This leads to privilege escalation because unprivileged processes can inject code into root processes.
CVE-2022-0847HIGHbajo ataque25 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
anldori/CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware25 abr 2022
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC1
Proof of concept exploit for CVE-2021-42697: Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.
CVE-2021-4269724 abr 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RIESGO
abrir
GitHub PoC
My research about CVE-2021-4034
CVE-2021-4034HIGHbajo ataque24 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC28
😭 WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.
CVE-2022-29464CRITICALbajo ataqueransomware24 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
h3x0v3rl0rd/CVE-2022-29464
CVE-2022-29464CRITICALbajo ataqueransomware24 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
h3x0v3rl0rd/CVE-2014-0160_Heartbleed
CVE-2014-0160HIGHbajo ataque24 abr 2022
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC5
Proof of concept exploit for CVE-2022-29548: A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.
CVE-2022-29548MEDIUM24 abr 2022
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RIESGO
abrir
anteriorpágina 317 / 461siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.