Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
77.813 exploits
GitHub PoC27
Oracle WebLogic Server 12.1.3.0.0 / 12.2.1.3.0 / 12.2.1.4.0 / 14.1.1.0.0 Local File Inclusion
CVE-2022-21371HIGH25 ene 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RIESGO
abrir
Exploit-DB
PHPIPAM 1.4.4 - SQLi (Authenticated)
CVE-2022-23046webappsphp25 ene 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RIESGO
abrir
Metasploit600
Local Privilege Escalation in polkits pkexec
CVE-2021-4034HIGHbajo ataqueransomware25 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware25 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-573625 ene 2022
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-21371HIGH25 ene 2022
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataqueransomware25 ene 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
GitHub PoC
Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read
CVE-2021-39312HIGH24 ene 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2021-39312HIGH24 ene 2022
True Ranker <= 2.2.2 Directory Traversal/Arbitrary File Read
78RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2022-21907CRITICAL23 ene 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-1881823 ene 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
GitHub PoC2
Strapi CMS 3.0.0-beta.17.4 - Unauthenticated Remote Code Execution (CVE-2019-18818, CVE-2019-19609)
CVE-2019-1960923 ene 2022
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
Metasploit300
Wordpress RegistrationMagic task_ids Authenticated SQLi
CVE-2021-2486223 ene 2022
RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection
60RIESGO
abrir
GitHub PoC28
CVE-2022-21907 Vulnerability PoC
CVE-2022-21907CRITICAL23 ene 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
GitHub PoC1
jcarabantes/CVE-2022-23046
CVE-2022-2304622 ene 2022
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su
28RIESGO
abrir
Metasploit600
Apache Couchdb Erlang RCE
CVE-2022-24706CRITICALbajo ataque21 ene 2022
Remote Code Execution Vulnerability in Packaging
100RIESGO
abrir
GitHub PoC5
test 反向辣鸡数据投放 CVE-2022-23305 工具 利用 教程 Exploit POC
CVE-2022-23305CRITICAL21 ene 2022
SQL injection in JDBC Appender in Apache Log4j V1
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2023-24489CRITICALbajo ataque20 ene 2022
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, coul
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque19 ene 2022
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
Metasploit600
Oracle Access Manager unauthenticated Remote Code Execution
CVE-2021-35587CRITICALbajo ataque19 ene 2022
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver
100RIESGO
abrir
GitHub PoC24
💀 Linux local root exploit for CVE-2018-18955
CVE-2018-1895519 ene 2022
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0185HIGHbajo ataque19 ene 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
GitHub PoC375
CVE-2022-0185
CVE-2022-0185HIGHbajo ataque19 ene 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-44228CRITICALbajo ataqueransomware18 ene 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
Exploit-DB
Creston Web Interface 1.0.0.2159 - Credential Disclosure
CVE-2022-23178webappshardware18 ene 2022
An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque18 ene 2022
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-1472MEDIUMbajo ataqueransomware18 ene 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque18 ene 2022
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2022-21661HIGH18 ene 2022
SQL injection in WordPress
78RIESGO
abrir
GitHub PoC83
Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers
CVE-2022-21907CRITICAL17 ene 2022
HTTP Protocol Stack Remote Code Execution Vulnerability
70RIESGO
abrir
anteriorpágina 614 / 2594siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.