Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC
cyberharsh/Tomcat-CVE-2017-12615
CVE-2017-12615HIGHbajo ataqueransomware24 jun 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC
cyberharsh/Groovy-scripting-engine-CVE-2015-1427
CVE-2015-1427CRITICALbajo ataque22 jun 2020
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC1
Python version of Metasploit exploit for CVE-2004-1561
CVE-2004-156122 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC
cdedmondson/Modified-CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware20 jun 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC3
cyberharsh/Nginx-CVE-2013-4547
CVE-2013-454720 jun 2020
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RIESGO
abrir
GitHub PoC1
cyberharsh/Apache-couchdb-CVE-2017-12635
CVE-2017-1263519 jun 2020
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC20
This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework
CVE-2020-0796CRITICALbajo ataqueransomware19 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC60
CVE-2020-8163 - Remote code execution of user-provided local names in Rails
CVE-2020-816319 jun 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir
GitHub PoC
cyberharsh/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL19 jun 2020
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
CVE-2018-7600 0-Day Exploit (cyber-warrior.org)
CVE-2018-7600CRITICALbajo ataqueransomware18 jun 2020
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC30
CVE-2020-5410 Spring Cloud Config directory traversal vulnerability
CVE-2020-5410HIGHbajo ataque16 jun 2020
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC721
Support ALL Windows Version
CVE-2020-0787HIGHbajo ataqueransomware16 jun 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
GitHub PoC86
LPE for CVE-2020-1054 targeting Windows 7 x64
CVE-2020-1054HIGHbajo ataque16 jun 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RIESGO
abrir
GitHub PoC1
A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing
CVE-2020-8816CRITICALbajo ataque15 jun 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC
Description and public exploit for CVE-2020-12712
CVE-2020-1271215 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RIESGO
abrir
GitHub PoC
sionnx/cve-2003-0282
CVE-2003-028214 jun 2020
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters bet
28RIESGO
abrir
GitHub PoC3
for 供養
CVE-2020-6418HIGHbajo ataque13 jun 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
GitHub PoC23
cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output
CVE-2020-0688HIGHbajo ataqueransomware12 jun 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
freshdemo/ApacheStruts-CVE-2018-11776
CVE-2018-11776HIGHbajo ataque12 jun 2020
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC
批量测试CVE-2020-0796 - SMBv3 RCE
CVE-2020-0796CRITICALbajo ataqueransomware11 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
Struts 2.5 - 2.5.12 REST Plugin XStream RCE
CVE-2017-9805HIGHbajo ataque11 jun 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
Norton Core Secure WiFi PoC (CVE-2018-5234) on Rust.
CVE-2018-523410 jun 2020
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir
GitHub PoC354
SMBGhost (CVE-2020-0796) Automate Exploitation and Detection
CVE-2020-0796CRITICALbajo ataqueransomware10 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC3
SMBv3 Ghost (CVE-2020-0796) Vulnerability
CVE-2020-0796CRITICALbajo ataqueransomware09 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
ratiros01/CVE-2004-1561
CVE-2004-156109 jun 2020
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RIESGO
abrir
GitHub PoC
适配12.2.1.3和12.2.1.4版本
CVE-2020-2883CRITICALbajo ataque09 jun 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC5
Bludit >= 3.9.2 - Authenticated RCE (CVE-2019-16113)
CVE-2019-1611309 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC3
This is the exploit of CVE-2019-17240.
CVE-2019-17240LOW08 jun 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC72
Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215
CVE-2019-2215HIGHbajo ataque07 jun 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC13
CVE-2019-16113 - bludit >= 3.9.2 RCE authenticate
CVE-2019-1611304 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
anteriorpágina 396 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.