Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
77.505 exploits
VulnCheck XDB
initial-access
CVE-2022-24706CRITICALbajo ataque17 nov 2022
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHbajo ataqueransomware17 nov 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-34473CRITICALbajo ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque16 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1
Resources required for building Pluralsight CVE-2022-0847 lab
CVE-2022-0847HIGHbajo ataque16 nov 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Metasploit600
Bitbucket Environment Variable RCE
CVE-2022-43781CRITICAL16 nov 2022
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
65RIESGO
abrir
Metasploit600
F5 BIG-IP iControl Authenticated RCE via RPM Creator
CVE-2022-41800HIGH16 nov 2022
Appliance mode iControl REST vulnerability
68RIESGO
abrir
GitHub PoC2
A massive scanner for CVE-2021-34473 Microsoft Exchange Windows Vulnerability
CVE-2021-34473CRITICALbajo ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit600
F5 BIG-IP iControl CSRF File Write SOAP API
CVE-2022-41622HIGH16 nov 2022
iControl SOAP vulnerability
58RIESGO
abrir
GitHub PoC4
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
CVE-2022-2463715 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
GitHub PoC3
A Golang program to automate the execution of CVE-2021-29447
CVE-2021-29447HIGH15 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC3
Social WarFare Plugin (<=3.5.2) Remote Code Execution
CVE-2019-9978MEDIUMbajo ataque15 nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC1
qq87234770/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque15 nov 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMbajo ataque15 nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque15 nov 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware15 nov 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware14 nov 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-41082HIGHbajo ataqueransomware14 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC7
mega8bit/exploit_cve-2021-29447
CVE-2021-29447HIGH14 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC
fall2022 secure coding CVE-2019-13272 : Linux Kernel Improper Privilege Management Vulnerability
CVE-2019-13272HIGHbajo ataque14 nov 2022
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC3
Microsoft Exchange Server Remote Code Execution Vulnerability.
CVE-2022-41082HIGHbajo ataqueransomware14 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC7
RCE exploit for WSO2
CVE-2022-29464CRITICALbajo ataqueransomware14 nov 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2020-1938CRITICALbajo ataque13 nov 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919313 nov 2022
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC1
CyberKimathi/Py3-CVE-2017-0785
CVE-2017-078513 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2017-12615HIGHbajo ataqueransomware13 nov 2022
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC
ivilpez/cve-2017-16995.c
CVE-2017-1699512 nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC359
Unsigned driver loader using CVE-2018-19320
CVE-2018-19320HIGHbajo ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
VulnCheck XDB
local
CVE-2018-19320HIGHbajo ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
Exploit-DB
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-24637webappsphp11 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
anteriorpágina 538 / 2584siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.