Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC38
CVE-2020-1938漏洞复现
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC54
Tomcat的文件包含及文件读取漏洞利用POC
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC2
h7hac9/CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque21 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC
Mass Exploit CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque20 feb 2020
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC295
Cnvd-2020-10487 / cve-2020-1938, scanner tool
CVE-2020-1938CRITICALbajo ataque20 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC45
xindongzhuaizhuai/CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque20 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC3
CVE-2020-1938
CVE-2020-1938CRITICALbajo ataque20 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
GitHub PoC45
CVE-2019-2729 Exploit Script
CVE-2019-2729CRITICAL19 feb 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
85RIESGO
abrir
GitHub PoC2
这篇文章将分享一个phpMyAdmin 4.8.1版本的文件包含漏洞,从配置到原理,再到漏洞复现进行讲解,更重要的是让大家了解这些真实漏洞背后的知识。基础性文章,希望对您有所帮助!
CVE-2018-1261319 feb 2020
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
GitHub PoC5
这篇文章将分享Windows远程桌面服务漏洞(CVE-2019-0708),并详细讲解该漏洞及防御措施。作者作为网络安全的小白,分享一些自学基础教程给大家,主要是关于安全工具和实践操作的在线笔记,希望您们喜欢。同时,更希望您能与我一起操作和进步,后续将深入学习网络安全和系统安全知识并分享相关实验。总之,希望该系列文章对博友有所帮助,写文不易,大神们不喜勿喷,谢谢!
CVE-2019-0708CRITICALbajo ataqueransomware19 feb 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC30
CVE-2020-0618 Honeypot
CVE-2020-0618CRITICALbajo ataque18 feb 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
GitHub PoC2
CVE-2020-0601 proof of concept
CVE-2020-0601HIGHbajo ataque18 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC5
Proof Of Concept Exploit for CVE-2020-7247 (Remote Execution on OpenSMTPD < 6.6.2
CVE-2020-7247CRITICALbajo ataque18 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC40
Android privilege escalation via an use-after-free in binder.c
CVE-2019-2215HIGHbajo ataque17 feb 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC4
OpenSMTPD version 6.6.2 remote code execution exploit
CVE-2020-7247CRITICALbajo ataque17 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC1
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,复现了该漏洞和理解恶意软件自启动劫持原理。作为网络安全初学者,自己确实很菜,但希望坚持下去,一起加油!
CVE-2020-0601HIGHbajo ataque17 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC30
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油!
CVE-2020-0601HIGHbajo ataque17 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC1
这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,复现了该漏洞和理解恶意软件自启动劫持原理。作为网络安全初学者,自己确实很菜,但希望坚持下去,一起加油!
CVE-2018-20250HIGHbajo ataqueransomware17 feb 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC3
Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995
CVE-2018-999515 feb 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC196
SQL Server Reporting Services(CVE-2020-0618)中的RCE
CVE-2020-0618CRITICALbajo ataque15 feb 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
GitHub PoC1
POE code for CVE-2017-1000112 adapted to both funtion on a specific VM and Escape a Docker
CVE-2017-100011214 feb 2020
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir
GitHub PoC2
User Enumeration Proof Of Concept Exploit for CVE-2019-8449
CVE-2019-844914 feb 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RIESGO
abrir
GitHub PoC2
An Python Exploit for Sudo vulnerability CVE-2019-18634
CVE-2019-1863413 feb 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
exploit for DNS 4.3
CVE-2013-698713 feb 2020
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RIESGO
abrir
GitHub PoC
PoC for CVE-2020-0601 vulnerability (Code Signing)
CVE-2020-0601HIGHbajo ataque12 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC3
PostgreSQL Remote Code Executuon
CVE-2019-919312 feb 2020
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC
N0b1e6/CVE-2018-1335-Python3
CVE-2018-133511 feb 2020
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193211 feb 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
CVE-2020-0683HIGHbajo ataque11 feb 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RIESGO
abrir
GitHub PoC3
VanillaForum 2.6.3 allows stored XSS.
CVE-2020-882510 feb 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir
anteriorpágina 406 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.