Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
13.812 exploits
GitHub PoC2
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVE-2022-22965CRITICALbajo ataque05 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC40
CVE-2021-22555 exploit rewritten with pipe primitive
CVE-2021-22555HIGHbajo ataque05 abr 2022
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
100RIESGO
abrir
GitHub PoC1
CVE-2022-22963 research
CVE-2022-22963CRITICALbajo ataque05 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC16
CVE-2022-0185 exploit rewritten with pipe primitive
CVE-2022-0185HIGHbajo ataque05 abr 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC3
Another spring4shell (Spring core RCE) POC
CVE-2022-22965CRITICALbajo ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Proof-of-concept exploit for CVE-2016-1827 on OS X Yosemite.
CVE-2016-182704 abr 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
GitHub PoC1
PowerShell port of CVE-2022-22965 vulnerability check by colincowie.
CVE-2022-22965CRITICALbajo ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
Intentionally vulnerable Spring app to test CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC7
CVE-2022-22965 (Spring4Shell) Proof of Concept
CVE-2022-22965CRITICALbajo ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
Spring4Shell - CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC12
Vulnerability scanner for Spring4Shell (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque04 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC128
A REAL DoS exploit for CVE-2022-21907
CVE-2022-21907CRITICAL04 abr 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
Linux “Dirty Pipe” vulnerability gives unprivileged users root access
CVE-2022-0847HIGHbajo ataque03 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC8
Nmap Spring4Shell NSE script for Spring Boot RCE (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque03 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC16
Docker PoC for CVE-2022-22965 with Spring Boot version 2.6.5
CVE-2022-22965CRITICALbajo ataque03 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
Spring Cloud Function SpEL - cve-2022-22963
CVE-2022-22963CRITICALbajo ataque03 abr 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182802 abr 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
GitHub PoC
mwojterski/cve-2022-22965
CVE-2022-22965CRITICALbajo ataque02 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC16
CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用
CVE-2022-22965CRITICALbajo ataque02 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Environment for CVE-2021-41773 recreation.
CVE-2021-41773HIGHbajo ataqueransomware02 abr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC11
CVE-2022-23131漏洞利用工具开箱即用。
CVE-2022-23131CRITICALbajo ataque02 abr 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC4
ShellShock interactive-shell exploit
CVE-2014-6271CRITICALbajo ataque02 abr 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC7
CVE-2022-22965 POC
CVE-2022-22965CRITICALbajo ataque02 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC10
tess-ss/SAP-memory-pipes-desynchronization-vulnerability-MPI-CVE-2022-22536
CVE-2022-22536CRITICALbajo ataque02 abr 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir
GitHub PoC7
DirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability is tracked as CVE-2022-0847 and allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root.
CVE-2022-0847HIGHbajo ataque02 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC18
ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。
CVE-2016-3088CRITICALbajo ataque02 abr 2022
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
GitHub PoC14
Spring Framework RCE via Data Binding on JDK 9+ / spring4shell / CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC2
Prova de conceito para a vulnerabilidade Polkit Pkexec: CVE-2021-4034(Pkexec Local Privilege Escalation)
CVE-2021-4034HIGHbajo ataque01 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC4
Spring-0day/CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC12
Spring4Shell (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque01 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
anteriorpágina 321 / 461siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.