Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC15
CVE-2019-0230 Exploit POC
CVE-2019-023013 ago 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
GitHub PoC13
[CVE-2020-6287] SAP NetWeaver AS JAVA (LM Configuration Wizard) Authentication Bypass (Create Simple & Administrator Java User)
CVE-2020-6287CRITICALbajo ataque13 ago 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC1
Vbulletin RCE Exploit
CVE-2019-16759CRITICALbajo ataque13 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC
polar1s7/CVE-2019-16759-bypass
CVE-2019-16759CRITICALbajo ataque12 ago 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC
Tobey123/CVE-2020-1472-visualizer
CVE-2020-1472MEDIUMbajo ataqueransomware12 ago 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE
CVE-2018-7600CRITICALbajo ataqueransomware10 ago 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC62
j4nn/CVE-2020-0041
CVE-2020-0041HIGHbajo ataque10 ago 2020
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could
71RIESGO
abrir
GitHub PoC17
CVE-2015-4852、CVE-2016-0638、CVE-2016-3510、CVE-2019-2890漏洞POC
CVE-2015-4852CRITICALbajo ataque10 ago 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
GitHub PoC2
CVE-2016-4010
CVE-2016-401010 ago 2020
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir
GitHub PoC3
CVE-2016-2555
CVE-2016-255509 ago 2020
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RIESGO
abrir
GitHub PoC25
PerimeterX/CVE-2020-6519
CVE-2020-651909 ago 2020
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RIESGO
abrir
GitHub PoC12
Automated F5 Big IP Remote Code Execution (CVE-2020-5902) Scanner Written In Python 3
CVE-2020-5902CRITICALbajo ataqueransomware09 ago 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC6
Webmin <=1.920 RCE
CVE-2019-15107CRITICALbajo ataqueransomware08 ago 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
漏洞复现
CVE-2018-2628CRITICALbajo ataque07 ago 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC
CVE-2013-3214
CVE-2013-321406 ago 2020
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RIESGO
abrir
GitHub PoC6
Pi-hole ( <= 4.3.2) authenticated remote code execution.
CVE-2020-8816CRITICALbajo ataque06 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC1
CVE-2017-8570 Exp改造及样本分析
CVE-2017-8570HIGHbajo ataque06 ago 2020
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
GitHub PoC1
Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original Exploit-DB/Metasploit module.
CVE-2016-9079HIGHbajo ataque06 ago 2020
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
GitHub PoC5
This was converted from a metasploit module as an exercise for OSCP studying
CVE-2012-298205 ago 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
GitHub PoC5
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.
CVE-2020-1595604 ago 2020
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RIESGO
abrir
GitHub PoC11
Pi-hole Remote Code Execution authenticated Version >= 4.3.2
CVE-2020-8816CRITICALbajo ataque04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC2
Solr_CVE-2019-17558
CVE-2019-17558HIGHbajo ataque04 ago 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
GitHub PoC1
CVE-2020-3452 - directory traversal in Cisco ASA and Cisco Firepower Threat Defense
CVE-2020-3452HIGHbajo ataque03 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC
Checks a list of SSH servers for password-based auth availability and for the existence of SSH user enumeration vulnerability (CVE-2018-15473) in those identified.
CVE-2018-15473MEDIUM03 ago 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
修改IP地址即可实现命令执行
CVE-2017-804601 ago 2020
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
GitHub PoC24
CVE-2020-3452 exploit
CVE-2020-3452HIGHbajo ataque01 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC42
POC for CVE-2020-13151
CVE-2020-1315101 ago 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
GitHub PoC15
ActiveMQ_putshell直接获取webshell
CVE-2016-3088CRITICALbajo ataque31 jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
GitHub PoC
ericisnotrealname/CVE-2018-8174_EXP
CVE-2018-8174HIGHbajo ataqueransomware31 jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC7
Shitrix : CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit
CVE-2019-19781CRITICALbajo ataqueransomware30 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
anteriorpágina 391 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.