Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque07 mar 2023
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2023-21716CRITICAL07 mar 2023
Microsoft Word Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC
rahmadsandy/EXIM-4.87-CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque07 mar 2023
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2017-11882HIGHbajo ataqueransomware06 mar 2023
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC1
Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.
CVE-2018-0802HIGHbajo ataqueransomware06 mar 2023
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL05 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC2
CVE-2022-31814
CVE-2022-31814CRITICAL05 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-138605 mar 2023
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RIESGO
abrir
GitHub PoC13
Laravel Debug mode RCE漏洞(CVE-2021-3129)poc / exp
CVE-2021-3129CRITICALbajo ataqueransomware04 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware04 mar 2023
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-21587CRITICALbajo ataqueransomware03 mar 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir
GitHub PoC6
This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)
CVE-2022-21587CRITICALbajo ataqueransomware03 mar 2023
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload).
100RIESGO
abrir
GitHub PoC
🚀 Exploit for Spring core RCE in C [ wip ]
CVE-2022-22965CRITICALbajo ataque02 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-0708CRITICALbajo ataqueransomware02 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
mritunjay-k/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque02 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware02 mar 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque02 mar 2023
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque02 mar 2023
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
Checker and exploit for Bluekeep CVE-2019-0708 vulnerability
CVE-2019-0708CRITICALbajo ataqueransomware02 mar 2023
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
An exploit for CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware02 mar 2023
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-31814CRITICAL01 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
VulnCheck XDB
local
CVE-2022-46689HIGH01 mar 2023
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macO
68RIESGO
abrir
GitHub PoC1
TheUnknownSoul/CVE-2022-31814
CVE-2022-31814CRITICAL01 mar 2023
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
GitHub PoC
A demonstration of CVE-2022-42889 (text4shell) remote code execution vulnerability
CVE-2022-4288901 mar 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC12
Joomla 未授权访问漏洞 CVE-2023-23752
CVE-2023-23752MEDIUMbajo ataque01 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2023-23752MEDIUMbajo ataque01 mar 2023
[20230201] - Core - Improper access check in webservice endpoints
100RIESGO
abrir
GitHub PoC10
BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748
CVE-2023-27746CRITICAL28 feb 2023
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracke
48RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-138628 feb 2023
Fusion Builder < 3.6.2 - Unauthenticated SSRF
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288928 feb 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC2
Kubernetes Lab for CVE-2022-42889
CVE-2022-4288928 feb 2023
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
anteriorpágina 521 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.