Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8703Nuclei 4314Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.724 exploits
VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗VulnCheck XDB
initial-access
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Exploit-DB
MyBB 1.8.29 - MyBB 1.8.29 - Remote Code Execution (RCE) (Authenticated)
Remote code execution in mybb
78RIESGO
abrir ↗Exploit-DB
Anuko Time Tracker - SQLi (Authenticated)
SQL injection in anuko timetracker
41RIESGO
abrir ↗GitHub PoC
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Exploit-DB
DLINK DIR850 - Open Redirect
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RIESGO
abrir ↗Exploit-DB
TLR-2005KSH - Arbitrary File Upload
TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa
50RIESGO
abrir ↗Exploit-DB
PHProjekt PhpSimplyGest v1.3. - Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB
SAP BusinessObjects Intelligence 4.3 - XML External Entity (XXE)
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RIESGO
abrir ↗Exploit-DB
ManageEngine ADSelfService Plus Build 6118 - NTLMv2 Hash Exposure
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131
23RIESGO
abrir ↗GitHub PoC
Research and proof of concept related to CVE-2022-1388.
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Exploit-DB
Akka HTTP 10.1.14 - Denial of Service
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, whic
35RIESGO
abrir ↗Exploit-DB
Explore CMS 1.0 - SQL Injection
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RIESGO
abrir ↗Exploit-DB
WebTareas 2.4 - Blind SQLi (Authenticated)
An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Advanced Uploader 4.2 - Arbitrary File Upload (Authenticated)
Advanced Uploader <= 4.2 - Subscriber+ Arbitrary File Upload
28RIESGO
abrir ↗GitHub PoC
This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Exploit-DB
ExifTool 12.23 - Arbitrary Code Execution
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir ↗GitHub PoC★ 7
A Zeek package to detect CVE-2022-26937, a vulnerability in the Network Lock Manager (NLM) protocol in Windows NFS server.
Windows Network File System Remote Code Execution Vulnerability
70RIESGO
abrir ↗Exploit-DB
DLINK DIR850 - Insecure Access Control
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote
35RIESGO
abrir ↗GitHub PoC
ShaikUsaf/external_expact_AOSP10_r33_CVE-2022-25315
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
48RIESGO
abrir ↗Exploit-DB
Cyclos 4.14.7 - 'groupId' DOM Based Cross-Site Scripting (XSS)
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wondershare Dr.Fone 12.0.7 - Privilege Escalation (ElevationService)
Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m
28RIESGO
abrir ↗GitHub PoC★ 5
AmirHoseinTangsiriNET/CVE-2022-1388-Scanner
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗GitHub PoC★ 2
CVE-2022-1388 Scanner
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir ↗Exploit-DB
Google Chrome 78.0.3904.70 - Remote Code Execution
Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap
83RIESGO
abrir ↗Exploit-DB
Ruijie Reyee Mesh Router - Remote Code Execution (RCE) (Authenticated)
A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191
35RIESGO
abrir ↗Exploit-DB
DLINK DAP-1620 A1 v1.01 - Directory Traversal
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]
50RIESGO
abrir ↗GitHub PoC★ 1
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir ↗VulnCheck XDB
initial-access
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RIESGO
abrir ↗Metasploit600
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.