Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC3
Different rules to detect if CVE-2021-31166 is being exploited
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
Nmap NSE script to detect CVE-2019-14322 of Pallets Werkzeug path traversal via SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames
CVE-2019-1432217 may 2021
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir
GitHub PoC8
PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.
CVE-2021-31166CRITICALbajo ataque17 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC53
PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282
CVE-2014-028217 may 2021
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir
GitHub PoC827
Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.
CVE-2021-31166CRITICALbajo ataque16 may 2021
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
GitHub PoC1
PoC of CVE-2019-14322: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-1432216 may 2021
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
50RIESGO
abrir
GitHub PoC2
Pega Infinity Password Reset
CVE-2021-27651CRITICAL16 may 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir
GitHub PoC60
RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2
CVE-2021-27651CRITICAL16 may 2021
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp
75RIESGO
abrir
GitHub PoC1
0xm4ud/ProFTPD_CVE-2015-3306
CVE-2015-330616 may 2021
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC4
Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority on Linux.
CVE-2017-7494CRITICALbajo ataqueransomware15 may 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC1
This is modified code of 46635 exploit from python2 to python3.
CVE-2019-905314 may 2021
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir
GitHub PoC6
CVE-2020-9496和CVE-2021-26295利用dnslog批量验证漏洞poc及exp
CVE-2020-949613 may 2021
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
GitHub PoC4
weblogic CVE-2021-2109批量验证poc
CVE-2021-2109HIGH13 may 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir
GitHub PoC236
Exploit to SYSTEM for CVE-2021-21551
CVE-2021-21551HIGHbajo ataque13 may 2021
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
GitHub PoC12
exiftool arbitrary code execution vulnerability
CVE-2021-22204MEDIUMbajo ataque12 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC97
Python exploit for the CVE-2021-22204 vulnerability in Exiftool
CVE-2021-22204MEDIUMbajo ataque11 may 2021
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
GitHub PoC1
0xm4ud/Cacti-CVE-2020-8813
CVE-2020-881311 may 2021
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
GitHub PoC3
Exploit for Node-jose < 0.11.0 written in Ruby
CVE-2018-011411 may 2021
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
GitHub PoC
fu2x2000/CVE-2017-17058-woo_exploit
CVE-2017-17058HIGH11 may 2021
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir
GitHub PoC3
POC Exploit written in Ruby
CVE-2019-542011 may 2021
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
GitHub PoC3
Check YouTube - https://youtu.be/O0ZnLXRY5Wo
CVE-2020-14882CRITICALbajo ataque10 may 2021
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC6
CVE-2017-7494 python exploit
CVE-2017-7494CRITICALbajo ataqueransomware09 may 2021
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC3
CVE-2019-2215
CVE-2019-2215HIGHbajo ataque07 may 2021
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC20
CVE-2019-1388 Abuse UAC Windows Certificate Dialog
CVE-2019-1388HIGHbajo ataqueransomware05 may 2021
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC
cve-2019-8942, cve-2019-8943
CVE-2019-894205 may 2021
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
GitHub PoC
ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build
CVE-2021-3156HIGHbajo ataque05 may 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
exploit
CVE-2019-1863405 may 2021
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC6
Atlassian Jira unauthen template injection
CVE-2019-11581CRITICALbajo ataque04 may 2021
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir
GitHub PoC
Docker-compose to set up a test environment for exploiting CVE-2015-8562
CVE-2015-856203 may 2021
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC1
事件: 微軟(Microsoft)上周公布了修補遭到駭客攻擊的 Exchange Server 漏洞,全球恐有數萬個組織受到影響。網域與被入侵的Exchange郵件伺服器有關,而這臺伺服器後來被駭客當作C&C中繼站使用,導致接下來發生加密攻擊事故。 嚴重性: 全球企業普遍使用微軟生態系執行日常業務,若遭受駭客攻擊,將造成用戶機敏資料外洩並導致極大損失。雖然微軟已推出更新補釘,但阿戴爾強調這尚未去除儲存在受害伺服器內的後門殼層(webshell),因此就算尚未受到攻擊的企業可以免於被駭風險,駭客仍有時間入侵已被駭的伺服器留下「定時炸彈」。 從2020年開始,美國便不斷指控中國入侵多家醫藥公司及學術單位,試圖竊取疫苗研發機密,這次事件很可能將使中美之間的關係進一步惡化。至於華為、TikTok等中國服務是否會受到這次駭客事件波及,則暫時還不明朗。 漏洞通報程序: 在2年前,曾經拿下資安圈漏洞奧斯卡獎Pwnie Awards「最佳伺服器漏洞獎」戴夫寇爾首席資安研究員Orange Tsai(蔡政達),漏洞通報記錄不勝枚舉,後來因為針對企業常用的SSL VPN進行漏洞研究與通報,更是在全球資安圈聲名大噪。 不過,在今年3月2日卻發生讓Orange Tsai錯愕不已的事情。那就是,他在今年一月跟微軟通報的2個Exchange漏洞,微軟原訂在3月9日對外釋出修補程式,卻突然提前一週,在3月2日便緊急釋出修補程式。原來是因為,在2月26日到2月28日,這個週五下班後到週末這段期間,全球各地發生許多利用微軟Exchange漏洞發動攻擊的資安事件。 攻擊本質: 有人在網路上大量掃描微軟於本月修補的CVE-2020-0688安全漏洞,該漏洞攸關Microsoft Exchange伺服器,呼籲Exchange用戶應儘速修補。 CVE-2020-0688漏洞肇因於Exchange伺服器在安裝時沒能妥善建立唯一金鑰,將允許具備該知識及信箱的授權用戶以系統權限傳遞任意物件,屬於遠端程式攻擊漏洞,該漏洞影響Microsoft Exchange Server 2010 SP3、Microsoft Exchange Server 2013、Microsoft Exchange Server 2016與Microsoft Exchange Server 2019,但只被微軟列為重要(Important)等級的風險。
CVE-2020-0688HIGHbajo ataqueransomware03 may 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
anteriorpágina 371 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.