Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
77.772 exploits
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque07 mar 2022
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC282
CVE-2022-0847-DirtyPipe-Exploit CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞,可覆盖重写任意可读文件中的数据,从而可将普通权限的用户提升到特权 root。 CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞(Dirty Cow),但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-24990CRITICALbajo ataqueransomware07 mar 2022
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen
100RIESGO
abrir
GitHub PoC9
CVE-2022-0847 exploit one liner
CVE-2022-0847HIGHbajo ataque07 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.29 or lower - Unauthenticated RCE chaining CVE-2022-24990 and CVE-2022-24989
CVE-2022-2498907 mar 2022
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst
30RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0492HIGHbajo ataque06 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
GitHub PoC113
Webmin <=1.984, CVE-2022-0824 Post-Auth Reverse Shell PoC
CVE-2022-0824HIGH06 mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir
GitHub PoC11
A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492
CVE-2022-0492HIGHbajo ataque06 mar 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
GitHub PoC2
22ke/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque05 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
日常更新一些顺手写的gobypoc,包含高危害EXP
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC2
Spring Cloud Gateway Actuator API 远程命令执行 CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC7
批量url检测Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC5
Greetdawn/CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3156HIGHbajo ataque04 mar 2022
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHbajo ataqueransomware04 mar 2022
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
Spring Cloud Gateway远程代码执行漏洞
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC
Exp
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC71
CVE-2022-22947批量
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
GitHub PoC9
cve-2022-22947 spring cloud gateway 批量扫描脚本
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware04 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
CVE-2019-11043 LAB
CVE-2019-11043HIGHbajo ataqueransomware04 mar 2022
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC8
9lyph/CVE-2022-29593
CVE-2022-29593MEDIUM04 mar 2022
relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques
38RIESGO
abrir
VulnCheck XDB
local
CVE-2021-40449HIGHbajo ataqueransomware04 mar 2022
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2022-22947批量检测脚本,回显命令没进行正则,大佬们先用着,后续再更
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-0185HIGHbajo ataque04 mar 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC3
Spring-Cloud-Gateway-CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque04 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
anteriorpágina 602 / 2593siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.