Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
77.533 exploits
GitHub PoC7
Automation to validate the impact of the vulnerability CVE-2022-1292 on a specific system.
CVE-2022-1292CRITICAL13 sep 2022
The c_rehash script allows command injection
70RIESGO
abrir
Metasploit500
Ubuntu Enlightenment Mount Priv Esc
CVE-2022-37706HIGH13 sep 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC8
POC exploit for CVE-2015-4133
CVE-2015-413312 sep 2022
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-3007512 sep 2022
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-27925HIGHbajo ataqueransomware12 sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
GitHub PoC1
M4fiaB0y/CVE-2022-30075
CVE-2022-3007512 sep 2022
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RIESGO
abrir
GitHub PoC323
A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)
CVE-2022-37706HIGH12 sep 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RIESGO
abrir
GitHub PoC3
CVE-2022-27925 nuclei template
CVE-2022-27925HIGHbajo ataqueransomware12 sep 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RIESGO
abrir
GitHub PoC2
CVE-2022-0847(Dirty Pipe) vulnerability exploits.
CVE-2022-0847HIGHbajo ataque11 sep 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque11 sep 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-38163CRITICALbajo ataque10 sep 2022
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir
GitHub PoC4
CVE-2021-38163 - exploit for SAP Netveawer
CVE-2021-38163CRITICALbajo ataque10 sep 2022
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2016-573410 sep 2022
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
GitHub PoC1
PhpMyAdmin 4.0.x—4.6.2 Remote Code Execution Vulnerability (CVE-2016-5734)
CVE-2016-573410 sep 2022
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque09 sep 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque09 sep 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
GitHub PoC
[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing
CVE-2014-6271CRITICALbajo ataque09 sep 2022
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC5
CVE-2022-31188 - OpenCV CVAT (Computer Vision Annotation Tool) SSRF
CVE-2022-31188HIGH09 sep 2022
Server-Side Request Forgery Vulnerability in Computer Vision Annotation Tool (CVAT)
53RIESGO
abrir
GitHub PoC3
CVE-2022-36446 - Webmin 1.996 Remote Code Execution
CVE-2022-3644609 sep 2022
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
GitHub PoC19
exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support
CVE-2017-1000486CRITICALbajo ataque09 sep 2022
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
GitHub PoC
This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.
CVE-2021-44228CRITICALbajo ataqueransomware08 sep 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-36804HIGHbajo ataque07 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
GitHub PoC35
A real exploit for BitBucket RCE CVE-2022-36804
CVE-2022-36804HIGHbajo ataque07 sep 2022
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Metasploit300
Syncovery For Linux Web-GUI Session Token Brute-Forcer
CVE-2022-3653606 sep 2022
An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be
18RIESGO
abrir
Metasploit600
Syncovery For Linux Web-GUI Authenticated Remote Command Execution
CVE-2022-3653406 sep 2022
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c
30RIESGO
abrir
GitHub PoC
Remediation for CVE-2013-3900
CVE-2013-3900MEDIUMbajo ataque06 sep 2022
WinVerifyTrust Signature Validation Vulnerability
75RIESGO
abrir
GitHub PoC1
Redis RCE through Lua Sandbox Escape vulnerability
CVE-2022-0543CRITICALbajo ataque05 sep 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
GitHub PoC23
CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation
CVE-2021-34527HIGHbajo ataqueransomware05 sep 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit500
pfSense plugin pfBlockerNG unauthenticated RCE as root
CVE-2022-31814CRITICAL05 sep 2022
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar
85RIESGO
abrir
VulnCheck XDB
local
CVE-2021-34527HIGHbajo ataqueransomware05 sep 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 554 / 2585siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.