Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
77.533 exploits
Exploit-DB
AVEVA InTouch Access Anywhere Secure Gateway 2020 R2 - Path Traversal
CVE-2022-23854HIGHremotehardware11 nov 2022
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
68RIESGO
abrir
Exploit-DB
MSNSwitch Firmware MNT.2408 - Remote Code Execution
CVE-2022-32429remotehardware11 nov 2022
An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog
60RIESGO
abrir
GitHub PoC4
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
CVE-2021-29447HIGH11 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC109
Zimbra <9.0.0.p27 RCE
CVE-2022-41352CRITICALbajo ataque11 nov 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir
Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
CVE-2022-38120MEDIUM10 nov 2022
POWERCOM CO., LTD. UPSMON PRO - Path Traversal
28RIESGO
abrir
Metasploit300
POWERCOM UPSMON PRO Path Traversal (CVE-2022-38120) and Credential Harvester (CVE-2022-38121)
CVE-2022-38121MEDIUM10 nov 2022
POWERCOM CO., LTD. UPSMON PRO - Insufficiently Protected Credentials
28RIESGO
abrir
GitHub PoC
Implementation of CVE-2022-30190 in C
CVE-2022-30190HIGHbajo ataqueransomware10 nov 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288910 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
SPRING DATA REST CVE-2017-8046 DEMO
CVE-2017-804610 nov 2022
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0185HIGHbajo ataque10 nov 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC
Joanmei/CVE-2017-0785
CVE-2017-078510 nov 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC1
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware09 nov 2022
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1
bantu2301/CVE-2018-16858
CVE-2018-16858HIGH09 nov 2022
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
Metasploit400
Lenovo Diagnostics Driver IOCTL memmove
CVE-2022-3699HIGH09 nov 2022
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RIESGO
abrir
GitHub PoC2
A simple tool to enumerate users in gitlab
CVE-2022-1162CRITICAL09 nov 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RIESGO
abrir
VulnCheck XDB
local
CVE-2022-3699HIGH09 nov 2022
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo
56RIESGO
abrir
GitHub PoC
The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661)
CVE-2022-21661HIGH08 nov 2022
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC1
DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"
CVE-2021-44228CRITICALbajo ataqueransomware08 nov 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque08 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC4
CVE-2022-22965图形化检测工具
CVE-2022-22965CRITICALbajo ataque08 nov 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Metasploit600
Acronis Cyber Protect/Backup remote code execution
CVE-2022-3405CRITICAL08 nov 2022
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
43RIESGO
abrir
GitHub PoC
CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit
CVE-2022-0824HIGH08 nov 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir
GitHub PoC2
yilin1203/CVE-2018-20062
CVE-2018-20062CRITICALbajo ataque07 nov 2022
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
GitHub PoC
adarshpv9746/Text4shell--Automated-exploit---CVE-2022-42889
CVE-2022-4288907 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
local
CVE-2022-4288907 nov 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-20062CRITICALbajo ataque07 nov 2022
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-2586MEDIUMbajo ataque06 nov 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque06 nov 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
GitHub PoC3
Arbitrary file read controller based on CVE-2021-29447
CVE-2021-29447HIGH06 nov 2022
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir
GitHub PoC3
gcc exploit.c -o exploit -lmnl -lnftnl -no-pie -lpthread
CVE-2022-2586MEDIUMbajo ataque06 nov 2022
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a
68RIESGO
abrir
anteriorpágina 540 / 2585siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.