Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
77.772 exploits
GitHub PoC28
This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
CVE-2022-1388CRITICALbajo ataqueransomware06 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC53
K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388
CVE-2022-1388CRITICALbajo ataqueransomware05 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC25
Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)
CVE-2022-1388CRITICALbajo ataqueransomware05 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware05 may 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware05 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-1388CRITICALbajo ataqueransomware05 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC1
1
CVE-2022-29464CRITICALbajo ataqueransomware05 may 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC
CVE-2022-22954 analyst
CVE-2022-22954CRITICALbajo ataqueransomware05 may 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
Metasploit600
F5 BIG-IP iControl RCE via REST Authentication Bypass
CVE-2022-1388CRITICALbajo ataqueransomware04 may 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
100RIESGO
abrir
GitHub PoC13
PoC of CVE-2022-24707
CVE-2022-24707HIGH03 may 2022
SQL injection in anuko timetracker
41RIESGO
abrir
Metasploit600
DotCMS RCE via Arbitrary File Upload.
CVE-2022-26352CRITICALbajo ataqueransomware03 may 2022
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22204MEDIUMbajo ataque03 may 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC
CVE-2018-17553 PoC
CVE-2018-1755303 may 2022
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RIESGO
abrir
GitHub PoC12
Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalation
CVE-2021-3560HIGHbajo ataque02 may 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque02 may 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC
Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware02 may 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC60
yuanLink/CVE-2022-26809
CVE-2022-26809CRITICAL01 may 2022
Remote Procedure Call Runtime Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC25
PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)
CVE-2021-3560HIGHbajo ataque30 abr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC1
CVE-2021-44228 Log4j Summary
CVE-2021-44228CRITICALbajo ataqueransomware30 abr 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque30 abr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque29 abr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
GitHub PoC8
This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.
CVE-2018-1942229 abr 2022
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir
VulnCheck XDB
local
CVE-2018-20250HIGHbajo ataqueransomware29 abr 2022
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC
Enokiy/spring-RCE-CVE-2022-22965
CVE-2022-22965CRITICALbajo ataque29 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALbajo ataqueransomware29 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC2
CVE-2022-29464 POC exploit
CVE-2022-29464CRITICALbajo ataqueransomware29 abr 2022
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RIESGO
abrir
GitHub PoC116
PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
CVE-2021-3560HIGHbajo ataque29 abr 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
Metasploit600
Zyxel Firewall ZTP Unauthenticated Command Injection
CVE-2022-30525CRITICALbajo ataque28 abr 2022
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque28 abr 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
RedLeavesChilde/CVE-2021-40444
CVE-2021-40444HIGHbajo ataqueransomware28 abr 2022
Microsoft MSHTML Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 584 / 2593siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.