Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC17
reversing mtk-su
CVE-2020-0069HIGHbajo ataque03 mar 2020
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient
71RIESGO
abrir
GitHub PoC181
POC for cve-2019-1458
CVE-2019-1458HIGHbajo ataqueransomware03 mar 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC132
CVE-2020-2546,CVE-2020-2915 CVE-2020-2801 CVE-2020-2798 CVE-2020-2883 CVE-2020-2884 CVE-2020-2950 WebLogic T3 payload exploit poc python3,
CVE-2020-2546CRITICAL02 mar 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - Java
48RIESGO
abrir
GitHub PoC11
This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.
CVE-2018-6789CRITICALbajo ataqueransomware02 mar 2020
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
GitHub PoC1
CVE-2019-5096(UAF in upload handler) exploit cause Denial of Service
CVE-2019-5096CRITICAL02 mar 2020
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go
60RIESGO
abrir
GitHub PoC353
Exploit and detect tools for CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware01 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC6
CVE-2020-1938(GhostCat) clean and readable code version
CVE-2020-1938CRITICALbajo ataque01 mar 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC11
HumanSecurity/CVE-2019-18426
CVE-2019-18426HIGHbajo ataque29 feb 2020
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RIESGO
abrir
GitHub PoC37
Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.
CVE-2020-0688HIGHbajo ataqueransomware28 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC1
I made this script for conducting CVE-2020-0688 more rapidly. It helps to improve checking the vuln, reducing hugely steps for that
CVE-2020-0688HIGHbajo ataqueransomware28 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC337
Weblogic IIOP CVE-2020-2551
CVE-2020-2551CRITICALbajo ataque28 feb 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Suppor
100RIESGO
abrir
GitHub PoC10
CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware28 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC2
Exchange Scanner CVE-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware27 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC144
CVE-2020-0688_EXP Auto trigger payload & encrypt method
CVE-2020-0688HIGHbajo ataqueransomware27 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC327
cve-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware27 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC5
Disclosure report of CVE-2020-9038
CVE-2020-903827 feb 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RIESGO
abrir
GitHub PoC1
Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)
CVE-2020-1938CRITICALbajo ataque26 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)
CVE-2020-0601HIGHbajo ataque26 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC66
CVE-2020-0688 - Exchange
CVE-2020-0688HIGHbajo ataqueransomware26 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
cve-2015-3306 docker image
CVE-2015-330625 feb 2020
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
Cette exploit en python va vous permettre de créer des listes de sites et les exploiter rapidement.
CVE-2018-15133HIGHbajo ataque25 feb 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC164
cve-2020-0688
CVE-2020-0688HIGHbajo ataqueransomware25 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC67
The official exploit for Cacti v1.2.8 Remote Code Execution CVE-2020-8813
CVE-2020-881322 feb 2020
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
GitHub PoC5
PoC exploit for CVE-2015-2291
CVE-2015-2291HIGHbajo ataqueransomware22 feb 2020
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
GitHub PoC3
CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本,批量验证,并自动截图,方便提交及复核
CVE-2020-1938CRITICALbajo ataque22 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC421
Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)
CVE-2020-1938CRITICALbajo ataque22 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC2
h7hac9/CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC54
Tomcat的文件包含及文件读取漏洞利用POC
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC38
CVE-2020-1938漏洞复现
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC11
在一定条件下可执行命令
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
anteriorpágina 405 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.