Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
77.813 exploits
GitHub PoC
CVE-2014-1767在win7_x64平台的EXP和分析文章
CVE-2014-176712 feb 2022
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RIESGO
abrir
Exploit-DB
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
CVE-2021-24931webappsphp10 feb 2022
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RIESGO
abrir
GitHub PoC
docker lab setup for kibana-7609
CVE-2019-7609CRITICALbajo ataque10 feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC
puckiestyle/CVE-2022-20699
CVE-2022-20699CRITICALbajo ataque10 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque10 feb 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALbajo ataque10 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
Exploit-DB
Hospital Management Startup 1.0 - 'Multiple' SQLi
CVE-2022-23366webappsphp10 feb 2022
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
23RIESGO
abrir
GitHub PoC2
An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.
CVE-2022-2508910 feb 2022
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RIESGO
abrir
Exploit-DB
AtomCMS v2.0 - SQLi
CVE-2022-24223webappsphp09 feb 2022
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RIESGO
abrir
Metasploit300
Strapi CMS Unauthenticated Password Reset
CVE-2019-1881809 feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Exploit-DB
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
CVE-2021-24901webappsphp08 feb 2022
Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
23RIESGO
abrir
GitHub PoC795
Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)
CVE-2022-21999HIGHbajo ataqueransomware08 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir
Exploit-DB
Hospital Management System 4.0 - 'multiple' SQL Injection
CVE-2022-24263webappsphp08 feb 2022
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RIESGO
abrir
Exploit-DB
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
CVE-2020-35749webappsphp08 feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir
Exploit-DB
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
CVE-2019-18818webappsnodejs08 feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Exploit-DB
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
CVE-2021-46398webappsmultiple08 feb 2022
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RIESGO
abrir
Metasploit300
CVE-2022-21999 SpoolFool Privesc
CVE-2022-21999HIGHbajo ataqueransomware08 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
CVE-2012-1876 win7_x86和x64平台分析,EXP、POC代码和分析文档
CVE-2012-187608 feb 2022
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware08 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Exploit-DB
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
CVE-2022-0448webappsphp08 feb 2022
CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
23RIESGO
abrir
VulnCheck XDB
local
CVE-2022-21999HIGHbajo ataqueransomware08 feb 2022
Windows Print Spooler Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
local
CVE-2022-21882HIGHbajo ataqueransomware07 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-20699CRITICALbajo ataque07 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
VulnCheck XDB
local
CVE-2015-132807 feb 2022
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
GitHub PoC2
Worm written in python, abuses CVE-2020-7247
CVE-2020-7247CRITICALbajo ataque07 feb 2022
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC10
kernel exploit
CVE-2015-132807 feb 2022
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir
Metasploit200
Netfilter nft_set_elem_init Heap Overflow Privilege Escalation
CVE-2022-3491807 feb 2022
An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff
38RIESGO
abrir
GitHub PoC237
Cisco Anyconnect VPN unauth RCE (rwx stack)
CVE-2022-20699CRITICALbajo ataque07 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
GitHub PoC49
lpe poc for cve-2022-21882
CVE-2022-21882HIGHbajo ataqueransomware07 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC6
Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit
CVE-2020-3574906 feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir
anteriorpágina 608 / 2594siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.