Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
77.772 exploits
GitHub PoC70
Bash script to check for CVE-2022-0847 "Dirty Pipe"
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1
Docker exploit
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC7
CVE-2022-24112: Apache APISIX Remote Code Execution Vulnerability
CVE-2022-24112CRITICALbajo ataque08 mar 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
GitHub PoC14
Implementation of Max Kellermann's exploit for CVE-2022-0847
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC2
puckiestyle/CVE-2022-0847
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC46
The Dirty Pipe Vulnerability
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
bohr777/cve-2022-0847dirtypipe-exploit
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
CVE-2022-0487
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1
lucksec/CVE-2022-0847
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC
zhangweijie11/CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque08 mar 2022
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC2
CVE-2022-24990:TerraMaster TOS 通过 PHP 对象实例化执行未经身份验证的远程命令
CVE-2022-24990CRITICALbajo ataqueransomware08 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware08 mar 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque08 mar 2022
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2021-31166CRITICALbajo ataque07 mar 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware07 mar 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque07 mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC1132
A root exploit for CVE-2022-0847 (Dirty Pipe)
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Exploit-DB
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
CVE-2022-22947CRITICALbajo ataquewebappsjava07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC50
CVE-2022-0847
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC282
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC9
Vulnerability in the Linux kernel since 5.8
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
GitHub PoC6
Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具
CVE-2022-22947CRITICALbajo ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
Exploit-DB
part-db 0.5.11 - Remote Code Execution (RCE)
CVE-2022-0848CRITICALwebappsphp07 mar 2022
OS Command Injection in part-db/part-db
60RIESGO
abrir
GitHub PoC1
SpringCloudGatewayRCE / Code By:Jun_sheng
CVE-2022-22947CRITICALbajo ataque07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-24990CRITICALbajo ataqueransomware07 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
anteriorpágina 601 / 2593siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.