Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
13.812 exploits
GitHub PoC
XSS via Host Header injection and Steal Password Reset Token of another user
CVE-2022-2418122 mar 2022
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RIESGO
abrir
GitHub PoC2
Dirty Pipe - CVE-2022-0847
CVE-2022-0847HIGHbajo ataque22 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
LTiDi2000/CVE-2020-2551
CVE-2020-2551CRITICALbajo ataque21 mar 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC1
SivaPriyaRanganatha/CVE-2020-6418
CVE-2020-6418HIGHbajo ataque21 mar 2022
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC18
Enokiy/cve-2022-22947-spring-cloud-gateway
CVE-2022-22947CRITICALbajo ataque21 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
Anonymous-Family/CVE-2015-1701-download
CVE-2015-1701HIGHbajo ataqueransomware21 mar 2022
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
GitHub PoC
Unspecified vulnerability in Microsoft Windows before 8 allows local users to gain privileges via unknown vectors, as exploited in the wild in April 2015 (Base Score: 7.2 HIGH) Current Description Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability
CVE-2015-1701HIGHbajo ataqueransomware21 mar 2022
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir
GitHub PoC4
pwncat module that automatically exploits CVE-2022-0847 (dirtypipe)
CVE-2022-0847HIGHbajo ataque20 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC12
CVE-2022-24990 TerraMaster TOS unauthenticated RCE via PHP Object Instantiation
CVE-2022-24990CRITICALbajo ataqueransomware20 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
GitHub PoC38
CVE-2022-24990信息泄露+RCE 一条龙
CVE-2022-24990CRITICALbajo ataqueransomware20 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
GitHub PoC3
RCE exploit for PHP Unit 5.6.2
CVE-2017-9841CRITICALbajo ataque20 mar 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC9
Apache APISIX < 2.12.1 Remote Code Execution and Docker Lab
CVE-2022-24112CRITICALbajo ataque20 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC
TheJoyOfHacking/saleemrashid-sudo-cve-2019-18634
CVE-2019-1863420 mar 2022
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
PoC for Dirty COW (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque19 mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
CVE-2016-182818 mar 2022
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir
GitHub PoC1
tzwlhack/CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware18 mar 2022
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC1
CVE-2021-3156
CVE-2021-3156HIGHbajo ataque18 mar 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC10
Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)
CVE-2022-0847HIGHbajo ataque18 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC18
CVE-2022-22947 memshell
CVE-2022-22947CRITICALbajo ataque18 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC4
Kibana <6.6.0 RCE written in python3
CVE-2019-7609CRITICALbajo ataque17 mar 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC2
Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token
CVE-2022-24112CRITICALbajo ataque17 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC11
CVE-2022-22947_POC_EXP
CVE-2022-22947CRITICALbajo ataque17 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC1
node-ipc is malware / protestware!
CVE-2022-23812CRITICAL17 mar 2022
Malicious Package
48RIESGO
abrir
GitHub PoC96
CVE-2022-0543_RCE,Redis Lua沙盒绕过 命令执行
CVE-2022-0543CRITICALbajo ataque16 mar 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
GitHub PoC15
Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit
CVE-2022-24112CRITICALbajo ataque16 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC15
Exploit for CVE-2022-27226
CVE-2022-2722616 mar 2022
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in
35RIESGO
abrir
GitHub PoC
si1ent-le/CVE-2019-5736
CVE-2019-573616 mar 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC3
Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847
CVE-2022-0847HIGHbajo ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC2
PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847
CVE-2022-0847HIGHbajo ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
NHPT/CVE-2022-24086-RCE
CVE-2022-24086CRITICALbajo ataque15 mar 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
anteriorpágina 324 / 461siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.