Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.587exploits catalogados
35.644CVEs con explotación pública
24.695probados en laboratorio
77.449 exploits
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque21 nov 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC7
修改版CVE-2022-0847
CVE-2022-0847HIGHbajo ataque21 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC5
Python Script to exploit RCE of CVE-2022-42889
CVE-2022-4288921 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
REMOTE CODE EXECUTION found in "OPTILINK OP-XT71000N".
CVE-2020-23583CRITICAL20 nov 2022
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary
48RIESGO
abrir
GitHub PoC
ARBITAR FILE UPLOAD LEADS TO "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse connection (using '.asp' webshell), backdoor , Escalation of Privileges, etc".
CVE-2020-23591CRITICAL20 nov 2022
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker t
48RIESGO
abrir
GitHub PoC
REMOTE CODE EXECUTION
CVE-2020-23584CRITICAL20 nov 2022
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes ar
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-30190HIGHbajo ataqueransomware19 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC8
A Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.
CVE-2022-30190HIGHbajo ataqueransomware19 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
CVE-2022-0441 - MasterStudy LMS 2.7.6
CVE-2022-044118 nov 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
GitHub PoC
wordpress docker
CVE-2016-10033CRITICALbajo ataque18 nov 2022
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-044118 nov 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware18 nov 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware18 nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49
CVE-2021-41773HIGHbajo ataqueransomware18 nov 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
Vulnerable configuration Apache HTTP Server version 2.4.49/2.4.50
CVE-2021-42013CRITICALbajo ataqueransomware18 nov 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC2
Abdulazizalsewedy/CVE-2021-29447
CVE-2021-29447HIGH17 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALbajo ataque17 nov 2022
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware17 nov 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHbajo ataqueransomware17 nov 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
A write-up of my (so far inconclusive) look into CVE-2022-31691
CVE-2022-31691CRITICAL17 nov 2022
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI
48RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque16 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-34473CRITICALbajo ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Resources required for building Pluralsight CVE-2022-0847 lab
CVE-2022-0847HIGHbajo ataque16 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC2
A massive scanner for CVE-2021-34473 Microsoft Exchange Windows Vulnerability
CVE-2021-34473CRITICALbajo ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
F5 BIG-IP iControl Authenticated RCE via RPM Creator
CVE-2022-41800HIGH16 nov 2022
Appliance mode iControl REST vulnerability
68RIESGO
abrir
Metasploit600
F5 BIG-IP iControl CSRF File Write SOAP API
CVE-2022-41622HIGH16 nov 2022
iControl SOAP vulnerability
58RIESGO
abrir
Metasploit600
Bitbucket Environment Variable RCE
CVE-2022-43781CRITICAL16 nov 2022
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
65RIESGO
abrir
GitHub PoC3
A Golang program to automate the execution of CVE-2021-29447
CVE-2021-29447HIGH15 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware15 nov 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC3
Social WarFare Plugin (<=3.5.2) Remote Code Execution
CVE-2019-9978MEDIUMbajo ataque15 nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
anteriorpágina 537 / 2582siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.