Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
8213 exploits
VulnCheck XDB
local
CVE-2021-40449HIGHbajo ataqueransomware04 mar 2022
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-0185HIGHbajo ataque04 mar 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio
76RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque03 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1472MEDIUMbajo ataqueransomware03 mar 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque03 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-22947CRITICALbajo ataque02 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque02 mar 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-100000101 mar 2022
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
VulnCheck XDB
local
CVE-2022-0492HIGHbajo ataque28 feb 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque28 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware28 feb 2022
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque28 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-24086CRITICALbajo ataque28 feb 2022
Adobe Commerce checkout improper input validation leads to remote code execution
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque28 feb 2022
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-41773HIGHbajo ataqueransomware27 feb 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-21971HIGHbajo ataque26 feb 2022
Windows Runtime Remote Code Execution Vulnerability
83RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-43798HIGHbajo ataque25 feb 2022
Grafana path traversal
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2022-2506025 feb 2022
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_sta
35RIESGO
abrir
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque25 feb 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
local
CVE-2021-4034HIGHbajo ataque25 feb 2022
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2021-44228CRITICALbajo ataqueransomware24 feb 2022
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque24 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2022-22242MEDIUM24 feb 2022
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque23 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-24112CRITICALbajo ataque22 feb 2022
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2022-23131CRITICALbajo ataque22 feb 2022
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware22 feb 2022
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2021-1675HIGHbajo ataqueransomware22 feb 2022
Windows Print Spooler Remote Code Execution Vulnerability
100RIESGO
abrir
anteriorpágina 196 / 274siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.