Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
77.724 exploits
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware28 may 2022
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-21661HIGH28 may 2022
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC10
CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合
CVE-2020-5902CRITICALbajo ataqueransomware28 may 2022
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC1
CVE-2022-1609 WordPress Weblizar后门
CVE-2022-1609CRITICAL27 may 2022
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALbajo ataque27 may 2022
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-063827 may 2022
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, an
35RIESGO
abrir
GitHub PoC
CVE-2018-17456复现
CVE-2018-1745627 may 2022
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL27 may 2022
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RIESGO
abrir
GitHub PoC2
FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523
CVE-2011-252327 may 2022
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
A PoC / methodology to exploit CVE-2017-6516
CVE-2017-651627 may 2022
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir
GitHub PoC1
sudo提权漏洞CVE-2021-3156复现代码
CVE-2021-3156HIGHbajo ataque26 may 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC5
Python script to exploit CVE-2022-29464 (mass mode)
CVE-2022-29464CRITICALbajo ataqueransomware26 may 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware26 may 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque26 may 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
yuuki1967/CVE-2021-44228-Apache-Log4j-Rce
CVE-2021-44228CRITICALbajo ataqueransomware25 may 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware25 may 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DBVexDay Proof
qdPM 9.1 - Remote Code Execution (RCE) (Authenticated) (v2)
CVE-2020-7246webappsphp25 may 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-0540CRITICAL25 may 2022
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RIESGO
abrir
GitHub PoC71
Atlassian Jira Seraph Authentication Bypass RCE(CVE-2022-0540)
CVE-2022-0540CRITICAL25 may 2022
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially
85RIESGO
abrir
GitHub PoC4
CVE-2022-1292
CVE-2022-1292CRITICAL24 may 2022
The c_rehash script allows command injection
70RIESGO
abrir
GitHub PoC
b1ackros337/CVE-2020-25213
CVE-2020-25213CRITICALbajo ataque24 may 2022
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-34473CRITICALbajo ataqueransomware24 may 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Metasploit300
SuiteCRM authenticated SQL injection in export functionality
CVE-2023-5350MEDIUM24 may 2022
SQL Injection in salesagility/suitecrm
28RIESGO
abrir
GitHub PoC
Satheesh575555/external_expat_AOSP10_r33_CVE-2022-25235
CVE-2022-25235CRITICAL24 may 2022
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT
48RIESGO
abrir
GitHub PoC1
SDT-CW3B1 1.1.0 - OS Command Injection
CVE-2021-4642224 may 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-4642224 may 2022
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-2297224 may 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
50RIESGO
abrir
GitHub PoC3
Initial POC for the CVE-2022-30525
CVE-2022-30525CRITICALbajo ataque23 may 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-30525CRITICALbajo ataque23 may 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
GitHub PoC1
Tinker Script for CVE-2022-23046
CVE-2022-2304623 may 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RIESGO
abrir
anteriorpágina 576 / 2591siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.