Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
77.533 exploits
VulnCheck XDB
initial-access
CVE-2022-4288923 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288923 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
local
CVE-2022-4204523 oct 2022
Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zeman
23RIESGO
abrir
GitHub PoC4
Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile
CVE-2022-4288923 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC5
Vulnerability Scanner for CVE-2022-42889 (Text4Shell)
CVE-2022-4288923 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC13
CVE-2022-39197 RCE POC
CVE-2022-39197MEDIUMbajo ataque22 oct 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC1
CVE-2022-42889 Text4Shell Exploit POC
CVE-2022-4288922 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
Dockerized PoC for CVE-2022-42889 Text4Shell
CVE-2022-4288922 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC3
python script for CVE-2022-42889
CVE-2022-4288922 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-39197MEDIUMbajo ataque22 oct 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
GitHub PoC
CVE-2017-0785
CVE-2017-078522 oct 2022
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1556822 oct 2022
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic cla
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288922 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-4288922 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-4288921 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC3
This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability
CVE-2022-4288921 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC2
humbss/CVE-2022-42889
CVE-2022-4288921 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
CVE-2007-4559 - Polemarch exploit
CVE-2007-4559CRITICAL21 oct 2022
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
53RIESGO
abrir
GitHub PoC8
Proof of Concept Appliction for testing CVE-2022-42889
CVE-2022-4288920 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
Automated Exploit for CVE-2017-9841 (eval-stdin.php vulnerable file)
CVE-2017-9841CRITICALbajo ataque20 oct 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHbajo ataqueransomware20 oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889
CVE-2022-4288920 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque20 oct 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC3
通过 jvm 启动参数 以及 jps pid进行拦截非法参数
CVE-2022-4288920 oct 2022
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC35
the metasploit script(POC) about CVE-2022-41040. Microsoft Exchange are vulnerable to a server-side request forgery (SSRF) attack. An authenticated attacker can use the vulnerability to elevate privileges.
CVE-2022-41040HIGHbajo ataqueransomware20 oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-7921CRITICALbajo ataque19 oct 2022
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC
inj3ction/CVE-2017-7921-EXP
CVE-2017-7921CRITICALbajo ataque19 oct 2022
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC2
Exploit updated to use Python 3.
CVE-2020-0688HIGHbajo ataqueransomware19 oct 2022
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware19 oct 2022
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-40684CRITICALbajo ataqueransomware19 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
anteriorpágina 543 / 2585siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.