Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC2
Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC7
批量url检测Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC3
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
CVE-2019-11043 LAB
CVE-2019-11043HIGHbajo ataqueransomware04 mar 2022
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
Test tool for CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC10
Spring cloud gateway code injection : CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC77
Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
poc for cve-2022-22947
CVE-2022-22947CRITICALbajo ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC28
SpringCloudGatewayRCE - CVE-2022-22947 / Code By:Tas9er
CVE-2022-22947CRITICALbajo ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC38
Spring Cloud Gateway < 3.0.7 & < 3.1.1 Code Injection (RCE)
CVE-2022-22947CRITICALbajo ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC1
Zero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.
CVE-2020-1472MEDIUMbajo ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
takumak/cve-2019-5736-reproducer
CVE-2019-573602 mar 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC4
A "Creation of Temporary Files in Directory with Insecure Permissions" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows any logged in user to elevate any executable or file to the SYSTEM context. This is achieved by exploiting race conditions in the Installer.
CVE-2022-2509002 mar 2022
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RIESGO
abrir
GitHub PoC223
CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque02 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
Tools for get offsets and adding patch for support i386
CVE-2018-100000101 mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
GitHub PoC15
Zabbix - SAML SSO Authentication Bypass
CVE-2022-23131CRITICALbajo ataque28 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC47
Test whether a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHbajo ataque28 feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
GitHub PoC
This script is intended to validate Apache Struts 2 vulnerability (CVE-2017-5638), AKA Struts-Shock.
CVE-2017-5638CRITICALbajo ataqueransomware28 feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
CVE-2022-24086 RCE
CVE-2022-24086CRITICALbajo ataque28 feb 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
GitHub PoC1
Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration
CVE-2019-2215HIGHbajo ataque28 feb 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
skentagon/CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware27 feb 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC1
Fa1c0n35/zabbix-cve-2022-23131
CVE-2022-23131CRITICALbajo ataque27 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC303
PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"
CVE-2022-21971HIGHbajo ataque26 feb 2022
Windows Runtime Remote Code Execution Vulnerability
83RIESGO
abrir
GitHub PoC8
Apache APISIX batch-requests RCE(CVE-2022-24112)
CVE-2022-24112CRITICALbajo ataque25 feb 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC1
Script to demonstrate the Grafana directory traversal exploit (CVE-2021-43798).
CVE-2021-43798HIGHbajo ataque25 feb 2022
Grafana path traversal
100RIESGO
abrir
GitHub PoC8
POC for CVE-2022-24124
CVE-2022-2412425 feb 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RIESGO
abrir
GitHub PoC1
trganda/CVE-2022-23131
CVE-2022-23131CRITICALbajo ataque24 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC2
pykiller/CVE-2022-23131
CVE-2022-23131CRITICALbajo ataque24 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC8
Zabbix SSO Bypass
CVE-2022-23131CRITICALbajo ataque23 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
anteriorpágina 330 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.