Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC3
Data Collection Related to Exim CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque03 jun 2020
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC5
ynots0ups/CVE-2019-16113
CVE-2019-1611303 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC
CVE-2020-5410
CVE-2020-5410HIGHbajo ataque03 jun 2020
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
GitHub PoC5
Exploit for CVE-2020-9283 based on Go
CVE-2020-928302 jun 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RIESGO
abrir
GitHub PoC
CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC
CVE-2020-0796-exp
CVE-2020-0796CRITICALbajo ataqueransomware02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC89
PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)
CVE-2020-395601 jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RIESGO
abrir
GitHub PoC3
nmurilo/CVE-2008-4687-exploit
CVE-2008-468730 may 2020
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
GitHub PoC2
This project for CVE-2019-18935
CVE-2019-18935CRITICALbajo ataqueransomware29 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
yukar1z0e/CVE-2017-15944
CVE-2017-15944CRITICALbajo ataque29 may 2020
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
GitHub PoC5
The reproduction code for CVE-2019-8641.
CVE-2019-864129 may 2020
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
GitHub PoC
halsten/CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware28 may 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC55
CVE-2016-4437-Shiro反序列化爆破模块和key,命令执行,反弹shell的脚本
CVE-2016-4437CRITICALbajo ataque27 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
GitHub PoC
gothburz/cve-2020-8617
CVE-2020-8617HIGH26 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
GitHub PoC
yukar1z0e/CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware26 may 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC13
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALbajo ataqueransomware25 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC87
QNAP pre-auth root RCE Exploit (CVE-2019-7192 ~ CVE-2019-7195)
CVE-2019-7192CRITICALbajo ataqueransomware24 may 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
GitHub PoC22
CVE-2020-2551 POC to use in Internet
CVE-2020-2551CRITICALbajo ataque24 may 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC5
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS)
CVE-2020-7961CRITICALbajo ataque23 may 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
GitHub PoC1
vulnerabilidad CVE-2019-0708 testing y explotacion
CVE-2019-0708CRITICALbajo ataqueransomware23 may 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
saltstack CVE-2020-11652
CVE-2020-11652MEDIUMbajo ataque22 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
GitHub PoC2
CVE-2017-17485:Jackson-databind RCE
CVE-2017-17485CRITICAL22 may 2020
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because o
60RIESGO
abrir
GitHub PoC
HKirito/phpmyadmin4.4_cve-2016-5734
CVE-2016-573422 may 2020
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir
GitHub PoC13
Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195)
CVE-2019-7192CRITICALbajo ataqueransomware21 may 2020
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
GitHub PoC45
PoC for CVE-2020-8617 (BIND)
CVE-2020-8617HIGH20 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
GitHub PoC105
Cisco AnyConnect < 4.8.02042 privilege escalation through path traversal
CVE-2020-3153MEDIUMbajo ataqueransomware19 may 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
GitHub PoC30
Tool to try multiple paths for PHPunit RCE CVE-2017-9841
CVE-2017-9841CRITICALbajo ataque18 may 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
yukar1z0e/CVE-2018-13379
CVE-2018-13379CRITICALbajo ataqueransomware18 may 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC
TelerikUI Vulnerability Scanner (CVE-2019-18935)
CVE-2019-18935CRITICALbajo ataqueransomware17 may 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC89
Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。
CVE-2020-2551CRITICALbajo ataque16 may 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
anteriorpágina 397 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.