Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
77.813 exploits
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware06 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware04 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware04 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Metasploit600
Docker cgroups Container Escape
CVE-2022-0492HIGHbajo ataque04 feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
GitHub PoC
IAmNewbieZ/CVE-2021-44228
CVE-2021-44228CRITICALbajo ataqueransomware04 feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Servisnet Tessa - Privilege Escalation (Metasploit)
CVE-2022-22833webappsmultiple04 feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.
28RIESGO
abrir
GitHub PoC
giardinas-dev/audit-xss-cve-2020-7934
CVE-2020-793404 feb 2022
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RIESGO
abrir
GitHub PoC8
PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python
CVE-2021-4034HIGHbajo ataqueransomware04 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Exploit-DB
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
CVE-2022-22832webappsmultiple04 feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RIESGO
abrir
GitHub PoC1
Apache HTTP Server 2.4.50 - RCE Lab
CVE-2021-42013CRITICALbajo ataqueransomware03 feb 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
GitHub PoC196
L4ys/CVE-2022-21882
CVE-2022-21882HIGHbajo ataqueransomware03 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC
Kayky-cmd/CVE-2019-6447--.
CVE-2019-644703 feb 2022
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-42013CRITICALbajo ataqueransomware03 feb 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware03 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-21882HIGHbajo ataqueransomware03 feb 2022
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
Exploit-DB
WordPress Plugin Contact Form Check Tester 1.0.2 - Broken Access Control
CVE-2021-24247webappsphp02 feb 2022
Contact Form Check Tester <= 1.0.2 - Broken Access Control to Cross-Site Scripting (XSS)
23RIESGO
abrir
Exploit-DB
WordPress Plugin Domain Check 1.0.16 - Reflected Cross-Site Scripting (XSS) (Authenticated)
CVE-2021-24926webappsphp02 feb 2022
Domain Check < 1.0.17 - Reflected Cross-Site Scripting
43RIESGO
abrir
Exploit-DB
WordPress Plugin Post Grid 2.1.1 - Cross Site Scripting (XSS)
CVE-2021-24488webappsphp02 feb 2022
Post Grid < 2.1.8 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
Exploit-DB
Moodle 3.11.4 - SQL Injection
CVE-2022-0332webappsphp02 feb 2022
A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv
35RIESGO
abrir
Exploit-DB
Chamilo LMS 1.11.14 - Account Takeover
CVE-2021-37391webappsphp02 feb 2022
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator
23RIESGO
abrir
Metasploit400
Cisco RV340 SSL VPN Unauthenticated Remote Code Execution
CVE-2022-20699CRITICALbajo ataque02 feb 2022
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
Exploit-DB
Mozilla Firefox 67 - Array.pop JIT Type Confusion
CVE-2019-11707HIGHbajo ataquelocalwindows02 feb 2022
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware02 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Exploit-DB
Wordpress Plugin 404 to 301 2.0.2 - SQL-Injection (Authenticated)
CVE-2015-9323webappsphp02 feb 2022
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
50RIESGO
abrir
Exploit-DB
Wordpress Plugin Download Monitor WordPress V 4.4.4 - SQL Injection (Authenticated)
CVE-2021-24786HIGHwebappsphp02 feb 2022
Download Monitor < 4.4.5 - Admin+ SQL Injection
61RIESGO
abrir
Exploit-DB
WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS)
CVE-2021-24300webappsphp02 feb 2022
PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware02 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
Exploit-DB
WordPress Plugin Learnpress 4.1.4.1 - Arbitrary Image Renaming
CVE-2022-0377webappsphp02 feb 2022
LearnPress < 4.1.5 - Arbitrary Image Renaming
23RIESGO
abrir
Exploit-DB
PHP Unit 4.8.28 - Remote Code Execution (RCE) (Unauthenticated)
CVE-2017-9841CRITICALbajo ataquewebappsphp02 feb 2022
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
Metasploit600
Zyxel chained RCE using LFI and weak password derivation algorithm
CVE-2023-28770HIGH01 feb 2022
The sensitive information exposure vulnerability in the CGI “Export_Log” and the binary “zcmd” in Zyxel DX5401-B0 firmwa
48RIESGO
abrir
anteriorpágina 609 / 2594siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.