Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
8198 exploits
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware15 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware15 oct 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware15 oct 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware15 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware15 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware15 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHbajo ataqueransomware14 oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware14 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware14 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-39197MEDIUMbajo ataque14 oct 2022
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att
75RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware13 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware13 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware13 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-40684CRITICALbajo ataqueransomware13 oct 2022
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALbajo ataque12 oct 2022
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque12 oct 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque12 oct 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0847HIGHbajo ataque11 oct 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-4045CRITICAL11 oct 2022
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-3129CRITICALbajo ataqueransomware11 oct 2022
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-41352CRITICALbajo ataque10 oct 2022
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque10 oct 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-35914CRITICALbajo ataque09 oct 2022
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHbajo ataqueransomware09 oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-26134CRITICALbajo ataqueransomware09 oct 2022
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2021-43798HIGHbajo ataque08 oct 2022
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-2687808 oct 2022
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41082HIGHbajo ataqueransomware07 oct 2022
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-1040CRITICALbajo ataque07 oct 2022
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-41040HIGHbajo ataqueransomware06 oct 2022
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
anteriorpágina 179 / 274siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.