Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC29
cve-2022-23131
CVE-2022-23131CRITICALbajo ataque22 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC2
mxypoo/CVE-2016-3116-DropbearSSH
CVE-2016-311622 feb 2022
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-c
28RIESGO
abrir
GitHub PoC
Apache APISIX apisix/batch-requests RCE
CVE-2022-24112CRITICALbajo ataque22 feb 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC43
CVE-2022-24112:Apache APISIX apisix/batch-requests RCE
CVE-2022-24112CRITICALbajo ataque22 feb 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC1
TheJoyOfHacking/dirkjanm-CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware22 feb 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
TheJoyOfHacking/SecuraBV-CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware22 feb 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
poc
CVE-2022-23131CRITICALbajo ataque21 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC
CVE-2019-15107 Webmin 1.920 RCE
CVE-2019-15107CRITICALbajo ataqueransomware21 feb 2022
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC35
CVE-2022-24086 about Magento RCE
CVE-2022-24086CRITICALbajo ataque20 feb 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
GitHub PoC3
An exploit for CVE-2020-6418 implementing a SHELF Loader. Published as part of Tmp.0ut volume 2
CVE-2020-6418HIGHbajo ataque19 feb 2022
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC95
cve-2022-23131 exp
CVE-2022-23131CRITICALbajo ataque18 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC3
1mxml/CVE-2022-23131
CVE-2022-23131CRITICALbajo ataque18 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC154
cve-2022-23131 zabbix-saml-bypass-exp
CVE-2022-23131CRITICALbajo ataque18 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC
qq1549176285/CVE-2022-23131
CVE-2022-23131CRITICALbajo ataque18 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
GitHub PoC37
CVE-2022-0185 POC and Docker and Analysis write up
CVE-2022-0185HIGHbajo ataque18 feb 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC
LeQuocKhanh2K/Tool_Exploit_Password_Camera_CVE-2018-9995
CVE-2018-999518 feb 2022
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC5
Hotel Druid 3.0.3 Code Injection to Remote Code Execution
CVE-2022-2290917 feb 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RIESGO
abrir
GitHub PoC1
An exploit script of CVE-2016-5195
CVE-2016-5195HIGHbajo ataque17 feb 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC
Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)
CVE-2021-44228CRITICALbajo ataqueransomware16 feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC
POC en Python para el CVE-2012-2982 mejorado del original por el usuario @OstojaOfficial
CVE-2012-298216 feb 2022
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC51
SAP memory pipes(MPI) desynchronization vulnerability CVE-2022-22536.
CVE-2022-22536CRITICALbajo ataque15 feb 2022
SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and
100RIESGO
abrir
GitHub PoC4
SQL Injection Vulnerability on PhpIPAM v1.4.4
CVE-2022-2304615 feb 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RIESGO
abrir
GitHub PoC
Build the struts-2.3.31 (CVE-2017-5638) environment
CVE-2017-5638CRITICALbajo ataqueransomware15 feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC6
r1l4-i3pur1l4/CVE-2022-21882
CVE-2022-21882HIGHbajo ataque14 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
Python exploit for CVE-2017-8917 - Joomla 3.7.0 'com_fields' SQL Injection
CVE-2017-891713 feb 2022
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
CVE-2014-176712 feb 2022
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RIESGO
abrir
GitHub PoC17
purple-WL/wordpress-CVE-2022-21661
CVE-2022-21661HIGH12 feb 2022
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC3
Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration
CVE-2021-44228CRITICALbajo ataqueransomware12 feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC1
purple-WL/Jenkins_CVE-2019-1003000
CVE-2019-100300012 feb 2022
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
GitHub PoC
docker lab setup for kibana-7609
CVE-2019-7609CRITICALbajo ataque10 feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
anteriorpágina 331 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.