Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
77.724 exploits
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-24734HIGHwebappsphp11 may 2022
Remote code execution in mybb
78RIESGO
abrir
Exploit-DB
Anuko Time Tracker - SQLi (Authenticated)
CVE-2022-24707HIGHwebappsphp11 may 2022
SQL injection in anuko timetracker
41RIESGO
abrir
GitHub PoC
CVE-2022-1388
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
DLINK DIR850 - Open Redirect
CVE-2021-46379remotehardware11 may 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RIESGO
abrir
Exploit-DB
TLR-2005KSH - Arbitrary File Upload
CVE-2021-45428webappshardware11 may 2022
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RIESGO
abrir
Exploit-DB
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
CVE-2022-27308webappsphp11 may 2022
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RIESGO
abrir
Exploit-DB
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
CVE-2022-28213remotemultiple11 may 2022
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RIESGO
abrir
Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
CVE-2022-29457remotewindows11 may 2022
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
23RIESGO
abrir
GitHub PoC
Research and proof of concept related to CVE-2022-1388.
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
CVE-2021-42697remotemultiple11 may 2022
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RIESGO
abrir
Exploit-DB
Explore CMS 1.0 - SQL Injection
CVE-2022-27412webappsphp11 may 2022
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RIESGO
abrir
Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
CVE-2021-43481webappsphp11 may 2022
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RIESGO
abrir
Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
CVE-2022-1103webappsphp11 may 2022
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RIESGO
abrir
GitHub PoC
This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
ExifTool 12.23 - Arbitrary Code Execution
CVE-2021-22204MEDIUMbajo ataquelocallinux11 may 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC7
A Zeek package to detect CVE-2022-26937, a vulnerability in the Network Lock Manager (NLM) protocol in Windows NFS server.
CVE-2022-26937CRITICAL11 may 2022
Windows Network File System Remote Code Execution Vulnerability
70RIESGO
abrir
Exploit-DB
DLINK DIR850 - Insecure Access Control
CVE-2021-46378remotehardware11 may 2022
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RIESGO
abrir
GitHub PoC
ShaikUsaf/external_expact_AOSP10_r33_CVE-2022-25315
CVE-2022-25315CRITICAL11 may 2022
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
48RIESGO
abrir
Exploit-DB
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
CVE-2021-31673webappsmultiple11 may 2022
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RIESGO
abrir
Exploit-DBVexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
CVE-2021-44595localwindows11 may 2022
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RIESGO
abrir
GitHub PoC5
AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC2
CVE-2022-1388 Scanner
CVE-2022-1388CRITICALbajo ataqueransomware11 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
Exploit-DB
Google Chrome 78.0.3904.70 - Remote Code Execution
CVE-2019-13720HIGHbajo ataqueremotemultiple11 may 2022
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RIESGO
abrir
Exploit-DB
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
CVE-2021-43164remotehardware11 may 2022
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RIESGO
abrir
Exploit-DB
DLINK DAP-1620 A1 v1.01 - Directory Traversal
CVE-2021-46381remotehardware11 may 2022
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RIESGO
abrir
GitHub PoC1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
CVE-2012-663611 may 2022
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2554010 may 2022
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RIESGO
abrir
Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
CVE-2022-37042CRITICALbajo ataqueransomware10 may 2022
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RIESGO
abrir
anteriorpágina 580 / 2591siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.