Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
77.531 exploits
Metasploit600
F5 BIG-IP iControl CSRF File Write SOAP API
CVE-2022-41622HIGH16 nov 2022
iControl SOAP vulnerability
58RIESGO
abrir
Metasploit600
Bitbucket Environment Variable RCE
CVE-2022-43781CRITICAL16 nov 2022
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker
65RIESGO
abrir
Metasploit600
F5 BIG-IP iControl Authenticated RCE via RPM Creator
CVE-2022-41800HIGH16 nov 2022
Appliance mode iControl REST vulnerability
68RIESGO
abrir
GitHub PoC2
A massive scanner for CVE-2021-34473 Microsoft Exchange Windows Vulnerability
CVE-2021-34473CRITICALbajo ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-34473CRITICALbajo ataqueransomware16 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque15 nov 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMbajo ataque15 nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC3
Social WarFare Plugin (<=3.5.2) Remote Code Execution
CVE-2019-9978MEDIUMbajo ataque15 nov 2022
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware15 nov 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC1
qq87234770/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque15 nov 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC3
A Golang program to automate the execution of CVE-2021-29447
CVE-2021-29447HIGH15 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC4
FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)
CVE-2022-2463715 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
GitHub PoC
fall2022 secure coding CVE-2019-13272 : Linux Kernel Improper Privilege Management Vulnerability
CVE-2019-13272HIGHbajo ataque14 nov 2022
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
GitHub PoC7
mega8bit/exploit_cve-2021-29447
CVE-2021-29447HIGH14 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware14 nov 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-41082HIGHbajo ataqueransomware14 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC7
RCE exploit for WSO2
CVE-2022-29464CRITICALbajo ataqueransomware14 nov 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC3
Microsoft Exchange Server Remote Code Execution Vulnerability.
CVE-2022-41082HIGHbajo ataqueransomware14 nov 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2017-12615HIGHbajo ataqueransomware13 nov 2022
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-919313 nov 2022
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC1
CyberKimathi/Py3-CVE-2017-0785
CVE-2017-078513 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC257
Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含
CVE-2020-1938CRITICALbajo ataque13 nov 2022
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-19320HIGHbajo ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
GitHub PoC
ivilpez/cve-2017-16995.c
CVE-2017-1699512 nov 2022
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC359
Unsigned driver loader using CVE-2018-19320
CVE-2018-19320HIGHbajo ataqueransomware12 nov 2022
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING
71RIESGO
abrir
Exploit-DB
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
CVE-2022-23854HIGHremotehardware11 nov 2022
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
68RIESGO
abrir
Exploit-DB
Open Web Analytics 1.7.3 - Remote Code Execution
CVE-2022-24637webappsphp11 nov 2022
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh
60RIESGO
abrir
Exploit-DB
SmartRG Router SR510n 2.6.13 - Remote Code Execution
CVE-2022-37661remotehardware11 nov 2022
SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
35RIESGO
abrir
Exploit-DB
MSNSwitch Firmware MNT.2408 - Remote Code Execution
CVE-2022-32429remotehardware11 nov 2022
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RIESGO
abrir
Exploit-DB
CVAT 2.0 - Server Side Request Forgery
CVE-2022-31188HIGHwebappspython11 nov 2022
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RIESGO
abrir
anteriorpágina 539 / 2585siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.