Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.460 exploits
Exploit-DB
Webmin 1.984 - Remote Code Execution (Authenticated)
CVE-2022-0824HIGHwebappslinux09 mar 2022
Improper Access Control to Remote Code Execution in webmin/webmin
78RIESGO
abrir
Exploit-DB
Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)
CVE-2022-0847HIGHbajo ataquelocallinux08 mar 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Exploit-DB
part-db 0.5.11 - Remote Code Execution (RCE)
CVE-2022-0848CRITICALwebappsphp07 mar 2022
OS Command Injection in part-db/part-db
60RIESGO
abrir
Exploit-DB
Spring Cloud Gateway 3.1.0 - Remote Code Execution (RCE)
CVE-2022-22947CRITICALbajo ataquewebappsjava07 mar 2022
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
Exploit-DB
Xerte 3.10.3 - Directory Traversal (Authenticated)
CVE-2021-44665webappsphp02 mar 2022
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via
23RIESGO
abrir
Exploit-DB
Zyxel ZyWALL 2 Plus Internet Security Appliance - Cross-Site Scripting (XSS)
CVE-2021-46387webappsmultiple02 mar 2022
ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t
43RIESGO
abrir
Exploit-DB
Xerte 3.9 - Remote Code Execution (RCE) (Authenticated)
CVE-2021-44664webappsphp02 mar 2022
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupl
28RIESGO
abrir
Exploit-DB
Casdoor 1.13.0 - SQL Injection (Unauthenticated)
CVE-2022-24124webappsmultiple28 feb 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d
50RIESGO
abrir
Exploit-DB
ICL ScadaFlex II SCADA Controllers SC-1/SC-2 1.03.07 - Remote File CRUD
CVE-2022-25359remotehardware23 feb 2022
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele
35RIESGO
abrir
Exploit-DB
WordPress Plugin WP User Frontend 3.5.25 - SQLi (Authenticated)
CVE-2021-25076webappsphp21 feb 2022
WP User Frontend < 3.5.26 - SQL Injection to Reflected Cross-Site Scripting
28RIESGO
abrir
Exploit-DB
Thinfinity VirtualUI 2.5.41.0 - IFRAME Injection
CVE-2021-45092webappsmultiple21 feb 2022
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RIESGO
abrir
Exploit-DB
Thinfinity VirtualUI 2.5.26.2 - Information Disclosure
CVE-2021-46354webappsmultiple21 feb 2022
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vuln
28RIESGO
abrir
Exploit-DB
FileCloud 21.2 - Cross-Site Request Forgery (CSRF)
CVE-2022-25241webappsphp21 feb 2022
In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
23RIESGO
abrir
Exploit-DB
WordPress Plugin Perfect Survey - 1.5.1 - SQLi (Unauthenticated)
CVE-2021-24762webappsphp21 feb 2022
Perfect Survey < 1.5.2 - Unauthenticated SQL Injection
60RIESGO
abrir
Exploit-DB
Hotel Druid 3.0.3 - Remote Code Execution (RCE)
CVE-2022-22909webappsphp18 feb 2022
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack
35RIESGO
abrir
Exploit-DB
WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation
CVE-2022-0441webappsphp18 feb 2022
MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account Creation
60RIESGO
abrir
Exploit-DB
Fortinet Fortimail 7.0.1 - Reflected Cross-Site Scripting (XSS)
CVE-2021-43062MEDIUMwebappsmultiple18 feb 2022
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0
53RIESGO
abrir
Exploit-DB
WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)
CVE-2021-24966webappsphp16 feb 2022
Error Log Viewer Plugin <= 1.1.1 - Admin+ Arbitrary File Clearing
23RIESGO
abrir
Exploit-DB
ServiceNow - Username Enumeration
CVE-2021-45901webappsmultiple16 feb 2022
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending
28RIESGO
abrir
Exploit-DB
WordPress Plugin Secure Copy Content Protection and Content Locking 2.8.1 - SQL-Injection (Unauthenticated)
CVE-2021-24931webappsphp10 feb 2022
Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL Injection
60RIESGO
abrir
Exploit-DB
Hospital Management Startup 1.0 - 'Multiple' SQLi
CVE-2022-23366webappsphp10 feb 2022
HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
23RIESGO
abrir
Exploit-DB
AtomCMS v2.0 - SQLi
CVE-2022-24223webappsphp09 feb 2022
AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
50RIESGO
abrir
Exploit-DB
Strapi CMS 3.0.0-beta.17.4 - Set Password (Unauthenticated) (Metasploit)
CVE-2019-18818webappsnodejs08 feb 2022
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Exploit-DB
WordPress Plugin Security Audit 1.0.0 - Stored Cross Site Scripting (XSS)
CVE-2021-24901webappsphp08 feb 2022
Security Audit <= 1.0.0 - Admin+ Stored Cross Site Scripting
23RIESGO
abrir
Exploit-DB
Hospital Management System 4.0 - 'multiple' SQL Injection
CVE-2022-24263webappsphp08 feb 2022
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m
23RIESGO
abrir
Exploit-DB
FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE)
CVE-2021-46398webappsmultiple08 feb 2022
A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use
23RIESGO
abrir
Exploit-DB
Wordpress Plugin Simple Job Board 2.9.3 - Local File Inclusion
CVE-2020-35749webappsphp08 feb 2022
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir
Exploit-DB
WordPress Plugin CP Blocks 1.0.14 - Stored Cross Site Scripting (XSS)
CVE-2022-0448webappsphp08 feb 2022
CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
23RIESGO
abrir
Exploit-DB
Servisnet Tessa - Privilege Escalation (Metasploit)
CVE-2022-22833webappsmultiple04 feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.
28RIESGO
abrir
Exploit-DB
Servisnet Tessa - MQTT Credentials Dump (Unauthenticated) (Metasploit)
CVE-2022-22832webappsmultiple04 feb 2022
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.