Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
77.772 exploits
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque17 mar 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque17 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token
CVE-2022-24112CRITICALbajo ataque17 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC11
CVE-2022-22947_POC_EXP
CVE-2022-22947CRITICALbajo ataque17 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC15
Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit
CVE-2022-24112CRITICALbajo ataque16 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware16 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Exploit-DB
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
CVE-2021-40964webappsphp16 mar 2022
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RIESGO
abrir
Exploit-DB
Tiny File Manager 2.4.6 - Remote Code Execution (RCE)
CVE-2021-45010webappsphp16 mar 2022
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7
45RIESGO
abrir
GitHub PoC96
CVE-2022-0543_RCE,Redis Lua沙盒绕过 命令执行
CVE-2022-0543CRITICALbajo ataque16 mar 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
GitHub PoC
si1ent-le/CVE-2019-5736
CVE-2019-573616 mar 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC15
Exploit for CVE-2022-27226
CVE-2022-2722616 mar 2022
A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALbajo ataque16 mar 2022
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-2198316 mar 2022
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authent
50RIESGO
abrir
Exploit-DB
Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-26965webappsphp16 mar 2022
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RIESGO
abrir
Exploit-DB
Apache APISIX 2.12.1 - Remote Code Execution (RCE)
CVE-2022-24112CRITICALbajo ataqueremotemultiple16 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC
NHPT/CVE-2022-24086-RCE
CVE-2022-24086CRITICALbajo ataque15 mar 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
GitHub PoC
githublihaha/DirtyPIPE-CVE-2022-0847
CVE-2022-0847HIGHbajo ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC2
PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847
CVE-2022-0847HIGHbajo ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1
bysinks/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque15 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-29441HIGH15 mar 2022
Authentication bypass
68RIESGO
abrir
GitHub PoC3
Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847
CVE-2022-0847HIGHbajo ataque15 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
Exploit for the Rails CVE-2019-5420
CVE-2019-542014 mar 2022
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware14 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC2
dirtypipe
CVE-2022-0847HIGHbajo ataque14 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware14 mar 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC2
Exploits for Hotel Druid 3.0.3 - Remote Code Execution (RCE) CVE-2022-22909
CVE-2022-2290914 mar 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RIESGO
abrir
Metasploit500
Watch Queue Out of Bounds Write
CVE-2022-099514 mar 2022
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This
38RIESGO
abrir
Metasploit300
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
CVE-2022-016914 mar 2022
Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL Injection
60RIESGO
abrir
GitHub PoC15
CVE-2022-0847 POC
CVE-2022-0847HIGHbajo ataque14 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC3
Implementation of CVE-2022-0847 as a shellcode
CVE-2022-0847HIGHbajo ataque14 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
anteriorpágina 598 / 2593siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.