Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
13.812 exploits
GitHub PoC8
Spring Cloud Function SPEL表达式注入漏洞(CVE-2022-22963)
CVE-2022-22963CRITICALbajo ataque14 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC1
Proof of Concept for exploiting VMware CVE-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware14 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC32
Detects attempts and successful exploitation of CVE-2022-26809
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC7
auduongxuan/CVE-2022-26809
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC27
Remote Code Execution Exploit in the RPC Library
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC3
CVE-2022-0185 exploit
CVE-2022-0185HIGHbajo ataque14 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC19
The poc for CVE-2022-26809 RCE via RPC will be updated here.
CVE-2022-26809CRITICAL14 abr 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
VVeakee/CVE-2017-12149
CVE-2017-12149CRITICALbajo ataqueransomware14 abr 2022
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC3
A Zeek detector for CVE-2022-24497.
CVE-2022-24497CRITICAL13 abr 2022
Windows Network File System Remote Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC3
Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure
CVE-2022-0482CRITICAL13 abr 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir
GitHub PoC68
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入
CVE-2022-22954CRITICALbajo ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC
VMware Workspace ONE Access远程代码执行漏洞 / Code By:Jun_sheng
CVE-2022-22954CRITICALbajo ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC16
VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.
CVE-2022-22954CRITICALbajo ataqueransomware13 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC2
AkuCyberSec/CVE-2017-8917-Joomla-370-SQL-Injection
CVE-2017-891713 abr 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC3
A Zeek CVE-2022-24491 detector.
CVE-2022-24491CRITICAL13 abr 2022
Windows Network File System Remote Code Execution Vulnerability
60RIESGO
abrir
GitHub PoC
exploitation script tryhackme
CVE-2022-22965CRITICALbajo ataque13 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Wangsafz/cve-2017-0358.sh
CVE-2017-0358HIGH12 abr 2022
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir
GitHub PoC1
Greenwolf/CVE-2022-1175
CVE-2022-1175HIGH12 abr 2022
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RIESGO
abrir
GitHub PoC4
Greenwolf/CVE-2022-1162
CVE-2022-1162CRITICAL12 abr 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RIESGO
abrir
GitHub PoC23
spring4shell | CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque12 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
TerraMaster TOS Unauthenticated Remote Command Execution(RCE) Vulnerability CVE-2022-24990
CVE-2022-24990CRITICALbajo ataqueransomware12 abr 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
GitHub PoC1
mumu2020629/-CVE-2022-22954-scanner
CVE-2022-22954CRITICALbajo ataqueransomware12 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC
lucksec/VMware-CVE-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware12 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC1
corelight/cve-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware12 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC12
提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码
CVE-2022-22954CRITICALbajo ataqueransomware12 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC10
PoC for CVE-2022-22954 - VMware Workspace ONE Access Freemarker Server-Side Template Injection
CVE-2022-22954CRITICALbajo ataqueransomware12 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC1
CVE-2022-22954 Açığı test etme
CVE-2022-22954CRITICALbajo ataqueransomware12 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC279
POC for VMWARE CVE-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware11 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC
G01d3nW01f/CVE-2022-22963
CVE-2022-22963CRITICALbajo ataque11 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC11
CVE-2022-22954 is a server-side template injection vulnerability in the VMware Workspace ONE Access and Identity Manager
CVE-2022-22954CRITICALbajo ataqueransomware11 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
anteriorpágina 319 / 461siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.