Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
77.772 exploits
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque08 abr 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware08 abr 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
GitHub PoC1
Ported golang version of dirtycow.c
CVE-2016-5195HIGHbajo ataque08 abr 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware08 abr 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-28281HIGH08 abr 2022
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent pr
41RIESGO
abrir
Exploit-DB
Sherpa Connector Service v2020.2.20328.2050 - Unquoted Service Path
CVE-2022-23909localwindows07 abr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-2865307 abr 2022
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution v
60RIESGO
abrir
GitHub PoC
Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测
CVE-2019-379907 abr 2022
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir
Exploit-DB
Kramer VIAware - Remote Code Execution (RCE) (Root)
CVE-2021-35064remotehardware07 abr 2022
KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn
60RIESGO
abrir
GitHub PoC101
Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC3
CalumHutton/CVE-2022-22965-PoC_Payara
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Exploit-DB
Kramer VIAware - Remote Code Execution (RCE) (Root)
CVE-2021-36356remotehardware07 abr 2022
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
50RIESGO
abrir
GitHub PoC63
CVE-2022-22965写入冰蝎webshell脚本
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC6
CVE-2022-22965 pocsuite3 POC
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
GitHub PoC
Spring4Shell PoC (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque07 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
Exploit-DB
binutils 2.37 - Objdump Segmentation Fault
CVE-2021-43149locallinux07 abr 2022
20RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque07 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
tmatejicek/CVE-2015-1397
CVE-2015-139707 abr 2022
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque06 abr 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Dirty Pipe Vulnerability Detection Script - RHSB-2022-002 Dirty Pipe - kernel arbitrary file manipulation - (CVE-2022-0847)
CVE-2022-0847HIGHbajo ataque06 abr 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1
sh-ubh/CVE-2018-1002105
CVE-2018-1002105CRITICAL06 abr 2022
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC3
Unquoted Service Path privilege escalation vulnerability in Sherpa Connector Service.
CVE-2022-2390906 abr 2022
There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might
23RIESGO
abrir
Metasploit400
VMware Workspace ONE Access CVE-2022-22960
CVE-2022-22960HIGHbajo ataque06 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RIESGO
abrir
Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
CVE-2022-2295606 abr 2022
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth
30RIESGO
abrir
Metasploit600
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
CVE-2022-2295706 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities
23RIESGO
abrir
Metasploit600
VMware Workspace ONE Access CVE-2022-22954
CVE-2022-22954CRITICALbajo ataqueransomware06 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
GitHub PoC2
The demo code showing the recent Spring4Shell RCE (CVE-2022-22965)
CVE-2022-22965CRITICALbajo ataque06 abr 2022
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-41773HIGHbajo ataqueransomware06 abr 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
anteriorpágina 590 / 2593siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.