Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
77.724 exploits
GitHub PoC4
Zyxel 防火墙未经身份验证的远程命令注入
CVE-2022-30525CRITICALbajo ataque13 may 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
GitHub PoC2
Melissa
CVE-2020-0618CRITICALbajo ataqueransomware13 may 2022
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
GitHub PoC
testaross4/CVE-2007-2447
CVE-2007-244713 may 2022
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-30525CRITICALbajo ataque13 may 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware13 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC22
Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)
CVE-2022-30525CRITICALbajo ataque13 may 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
GitHub PoC33
Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)批量检测脚本
CVE-2022-30525CRITICALbajo ataque13 may 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware12 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware12 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware12 may 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware12 may 2022
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
CVE-2021-41773 Shodan scanner
CVE-2021-41773HIGHbajo ataqueransomware12 may 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Exploit-DB
Royal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)
CVE-2022-28080webappsphp12 may 2022
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
50RIESGO
abrir
GitHub PoC2
Essay (and PoCs) about CVE-2021-41773, a remote code execution vulnerability in Apache 2.4.49 🕸️
CVE-2021-41773HIGHbajo ataqueransomware12 may 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC6
Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services
CVE-2022-26923HIGHbajo ataque12 may 2022
Active Directory Domain Services Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
F5 BIG-IP 16.0.x - Remote Code Execution (RCE)
CVE-2022-1388CRITICALbajo ataqueransomwareremotemultiple12 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
College Management System 1.0 - 'course_code' SQL Injection (Authenticated)
CVE-2022-28079webappsphp12 may 2022
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
43RIESGO
abrir
GitHub PoC13
F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB
CVE-2022-1388CRITICALbajo ataqueransomware12 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC2
Nuclei Template for CVE-2022-1388
CVE-2022-1388CRITICALbajo ataqueransomware12 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC
CVE-2020-0688_Microsoft Exchange default MachineKeySection deserialize vulnerability
CVE-2020-0688HIGHbajo ataqueransomware12 may 2022
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DB
TLR-2005KSH - Arbitrary File Delete
CVE-2021-46424webappshardware12 may 2022
Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de
50RIESGO
abrir
Exploit-DB
WordPress Plugin Blue Admin 21.06.01 - Cross-Site Request Forgery (CSRF)
CVE-2021-24581webappsphp11 may 2022
Blue Admin <= 21.06.01 - CSRF to Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
Exploit-DB
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43164remotehardware11 may 2022
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RIESGO
abrir
GitHub PoC1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2013-471011 may 2022
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir
Exploit-DBVexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
CVE-2021-44595localwindows11 may 2022
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RIESGO
abrir
Exploit-DB
DLINK DIR850 - Insecure Access Control
CVE-2021-46378remotehardware11 may 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RIESGO
abrir
GitHub PoC7
A Zeek package to detect CVE-2022-26937, a vulnerability in the Network Lock Manager (NLM) protocol in Windows NFS server.
CVE-2022-26937CRITICAL11 may 2022
Windows Network File System Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC2
CVE-2022-1388 Scanner
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
CVE-2021-43481webappsphp11 may 2022
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RIESGO
abrir
Exploit-DB
Anuko Time Tracker - SQLi (Authenticated)
CVE-2022-24707HIGHwebappsphp11 may 2022
SQL injection in anuko timetracker
41RIESGO
abrir
anteriorpágina 579 / 2591siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.