Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
GitHub PoC4
Remote Code Execution in Social Warfare Plugin before 3.5.3 for Wordpress.
CVE-2019-9978MEDIUMbajo ataque20 ene 2023
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2022-42864HIGH19 ene 2023
A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, ma
41RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALbajo ataqueransomware19 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
GitHub PoC
PoC for cve-2022-47966
CVE-2022-47966CRITICALbajo ataqueransomware19 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
Metasploit600
Sudoedit Extra Arguments Priv Esc
CVE-2023-22809HIGH18 ene 2023
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environmen
68RIESGO
abrir
Metasploit600
Oracle Weblogic PreAuth Remote Command Execution via ForeignOpaqueReference IIOP Deserialization
CVE-2023-21839HIGHbajo ataque17 ene 2023
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
100RIESGO
abrir
GitHub PoC
notareaperbutDR34P3r/CVE-2022-40684-Rust
CVE-2022-40684CRITICALbajo ataqueransomware17 ene 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC2
A POC on how to exploit CVE-2022-27518
CVE-2022-27518CRITICALbajo ataque17 ene 2023
Unauthenticated remote arbitrary code execution
78RIESGO
abrir
GitHub PoC1
test for the ioc described for FG-IR-22-398
CVE-2022-42475CRITICALbajo ataqueransomware17 ene 2023
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0
100RIESGO
abrir
GitHub PoC2
CVE-2014-5460
CVE-2014-546017 ene 2023
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir
GitHub PoC129
POC for CVE-2022-47966 affecting multiple ManageEngine products
CVE-2022-47966CRITICALbajo ataqueransomware17 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-47966CRITICALbajo ataqueransomware17 ene 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware17 ene 2023
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
GitHub PoC
Project for the Cyberspace Security class.
CVE-2017-891717 ene 2023
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC3
RCE POC for CVE-2022-46169
CVE-2022-46169CRITICALbajo ataque16 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC
Exploit For OverlayFS
CVE-2021-3493HIGHbajo ataque16 ene 2023
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque16 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22963CRITICALbajo ataque15 ene 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware15 ene 2023
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque15 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC2
Cacti: Unauthenticated Remote Code Execution Exploit in Ruby
CVE-2022-46169CRITICALbajo ataque15 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC4
iliass-dahman/CVE-2022-22963-POC
CVE-2022-22963CRITICALbajo ataque15 ene 2023
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po
100RIESGO
abrir
GitHub PoC3
cbk914/CVE-2022-26134_check
CVE-2022-26134CRITICALbajo ataqueransomware15 ene 2023
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC2
cbk914/CVE-2022-30525_check
CVE-2022-30525CRITICALbajo ataque15 ene 2023
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
GitHub PoC
nhamle2/CVE-2015-8660
CVE-2015-866015 ene 2023
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-2227414 ene 2023
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2024-4577CRITICALbajo ataqueransomware13 ene 2023
Argument Injection in PHP-CGI
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-46169CRITICALbajo ataque13 ene 2023
Unauthenticated Command Injection
100RIESGO
abrir
GitHub PoC1
CVE 2022-45299
CVE-2022-45299CRITICAL13 ene 2023
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-21661HIGH13 ene 2023
SQL injection in WordPress
78RIESGO
abrir
anteriorpágina 529 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.