Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
13.885 exploits
GitHub PoC
docker lab setup for kibana-7609
CVE-2019-7609CRITICALbajo ataque10 feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC2
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
CVE-2022-2508910 feb 2022
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RIESGO
abrir
GitHub PoC795
Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)
CVE-2022-21999HIGHbajo ataqueransomware08 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
CVE-2012-1876 win7_x86和x64平台分析,EXP、POC代码和分析文档
CVE-2012-187608 feb 2022
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir
GitHub PoC2
Worm written in python, abuses CVE-2020-7247
CVE-2020-7247CRITICALbajo ataque07 feb 2022
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC10
kernel exploit
CVE-2015-132807 feb 2022
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC237
Cisco Anyconnect VPN unauth RCE (rwx stack)
CVE-2022-20699CRITICALbajo ataque07 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
GitHub PoC49
lpe poc for cve-2022-21882
CVE-2022-21882HIGHbajo ataque07 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC6
Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit
CVE-2020-3574906 feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir
GitHub PoC
giardinas-dev/audit-xss-cve-2020-7934
CVE-2020-793404 feb 2022
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RIESGO
abrir
GitHub PoC
IAmNewbieZ/CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware04 feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC8
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python
CVE-2021-4034HIGHbajo ataque04 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC1
Apache HTTP Server 2.4.50 - RCE Lab
CVE-2021-42013CRITICALbajo ataqueransomware03 feb 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
Kayky-cmd/CVE-2019-6447--.
CVE-2019-644703 feb 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
GitHub PoC196
L4ys/CVE-2022-21882
CVE-2022-21882HIGHbajo ataque03 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
qkrtjsrbs315/CVE-2013-1763
CVE-2013-176301 feb 2022
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RIESGO
abrir
GitHub PoC8
CVE-2022-21882
CVE-2022-21882HIGHbajo ataque01 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
Study on Linux kernel code injection via CVE-2014-3153 (Towelroot)
CVE-2014-3153HIGHbajo ataque01 feb 2022
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC9
CVE-2021-3560 analysis
CVE-2021-3560HIGHbajo ataque31 ene 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.
CVE-2017-0213HIGHbajo ataqueransomware29 ene 2022
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
GitHub PoC3
CVE-2013-3660的x64 win7平台EXP源代码,成功率100%。
CVE-2013-3660HIGHbajo ataque29 ene 2022
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir
GitHub PoC1
pwnkit
CVE-2021-4034HIGHbajo ataque28 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
galoget/PwnKit-CVE-2021-4034
CVE-2021-4034HIGHbajo ataque28 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
BrunoPincho/cve-2018-16763-rust
CVE-2018-1676327 ene 2022
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
GitHub PoC4
CVE-2021-4034 PoC , polkit < 0.131
CVE-2021-4034HIGHbajo ataque27 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
khaclep007/CVE-2022-0185
CVE-2022-0185HIGHbajo ataque27 ene 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC351
Proof of concept for pwnkit vulnerability
CVE-2021-4034HIGHbajo ataque27 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC462
win32k LPE
CVE-2022-21882HIGHbajo ataque27 ene 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC11
CVE-2021-3156 POC and Docker and Analysis write up
CVE-2021-3156HIGHbajo ataque27 ene 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689
CVE-2018-1400927 ene 2022
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RIESGO
abrir
anteriorpágina 332 / 463siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.