Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
77.772 exploits
Exploit-DB
Zyxel NWA-1100-NH - Command Injection
CVE-2021-4039CRITICALremotehardware19 abr 2022
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to exec
70RIESGO
abrir
Exploit-DB
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
CVE-2022-24181webappsphp19 abr 2022
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to
38RIESGO
abrir
Exploit-DB
WordPress Plugin Popup Maker 1.16.5 - Stored Cross-Site Scripting (Authenticated)
CVE-2022-1104webappsphp19 abr 2022
Popup Maker < 1.16.5 - Admin+ Stored Cross-Site Scripting
35RIESGO
abrir
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34877MEDIUM19 abr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contains a SQL injection vulnerability at /vicidial/AST_agent_time_sheet.php.
28RIESGO
abrir
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34876MEDIUM19 abr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contain multiple SQL injection vulnerability at /vicidial/admin.php.
28RIESGO
abrir
GitHub PoC
ms15-034 or CVE-2015-1635 批量扫描
CVE-2015-1635CRITICALbajo ataque19 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Metasploit300
VICIdial Multiple Authenticated SQLi
CVE-2022-34878MEDIUM19 abr 2022
VICIDial 2.14b0.5 SVN 3550 was discovered to contain a SQL injection vulnerability at /vicidial/user_stats.php.
28RIESGO
abrir
GitHub PoC2
Watchguard RCE POC CVE-2022-26318
CVE-2022-26318CRITICALbajo ataque18 abr 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware18 abr 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC
CVE-2021-42013 - Apache 2.4.50
CVE-2021-42013CRITICALbajo ataqueransomware18 abr 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22205CRITICALbajo ataqueransomware18 abr 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26318CRITICALbajo ataque18 abr 2022
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner
100RIESGO
abrir
GitHub PoC
CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware18 abr 2022
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3180518 abr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALbajo ataque17 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC1
CVE-2015-1635-POC,指定IP与端口验证HTTP.sys漏洞是否存在
CVE-2015-1635CRITICALbajo ataque17 abr 2022
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC9
Scripted Linux Privilege Escalation for the CVE-2022-0847 "Dirty Pipe" vulnerability
CVE-2022-0847HIGHbajo ataque17 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware16 abr 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44529CRITICALbajo ataqueransomware16 abr 2022
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir
GitHub PoC2
Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution. The vulnerability affects the kernel module http. sys, which handles most basic IIS operations.
CVE-2022-21907CRITICAL16 abr 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC53
Exploit for CVE-2021-22204 (ExifTool) - Arbitrary Code Execution
CVE-2021-22204MEDIUMbajo ataque16 abr 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC
mhurts/CVE-2022-22954-POC
CVE-2022-22954CRITICALbajo ataqueransomware16 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-22204MEDIUMbajo ataque16 abr 2022
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC148
Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
CVE-2021-3129CRITICALbajo ataqueransomware16 abr 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC4
CVE-2022-22954 VMware Workspace ONE Access free marker SSTI
CVE-2022-22954CRITICALbajo ataqueransomware15 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3180515 abr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3180515 abr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3180515 abr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3180515 abr 2022
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque15 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
anteriorpágina 587 / 2593siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.