Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
82.419 exploits
VulnCheck XDB
initial-access
CVE-2021-2109HIGH21 dic 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque21 dic 2023
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-2109HIGH21 dic 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2017-5753MEDIUM21 dic 2023
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware21 dic 2023
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware21 dic 2023
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2021-31728—21 dic 2023
Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to
23RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-0230—21 dic 2023
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2017-8917—21 dic 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2009-3103—20 dic 2023
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—20 dic 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-30190HIGHbajo ataqueransomware20 dic 2023
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-25157CRITICAL20 dic 2023
Unfiltered SQL Injection Vulnerabilities in Geoserver
85RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-33246CRITICALbajo ataque20 dic 2023
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2023-22809HIGH20 dic 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2017-5753MEDIUM20 dic 2023
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir ↗
VulnCheck XDB
local
CVE-2017-5753MEDIUM20 dic 2023
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-34362CRITICALbajo ataqueransomware20 dic 2023
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-38408CRITICAL20 dic 2023
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remot
70RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-42889—20 dic 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque20 dic 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-45699CRITICAL20 dic 2023
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack
85RIESGO
abrir ↗
VulnCheck XDB
denial-of-service
CVE-2023-27997CRITICALbajo ataqueransomware20 dic 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, versi
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22954CRITICALbajo ataqueransomware20 dic 2023
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-2825CRITICAL20 dic 2023
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
85RIESGO
abrir ↗
Metasploit600
Cacti RCE via SQLi in pollers.php
CVE-2023-49085HIGH20 dic 2023
Cacti SQL Injection vulnerability
58RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27524HIGHbajo ataque20 dic 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RIESGO
abrir ↗
Metasploit600
Cacti RCE via SQLi in pollers.php
CVE-2023-49084HIGH20 dic 2023
Local File Inclusion (RCE) in Cacti
48RIESGO
abrir ↗
VulnCheck XDB
client-side
CVE-2022-28368—20 dic 2023
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RIESGO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque20 dic 2023
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir ↗
← anteriorpágina 517 / 2748siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.