Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC7
Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.
CVE-2019-1428709 feb 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
Exhaust WordPress <V5.0.1 resources using long passwords (CVE-2014-9016)
CVE-2014-901608 feb 2020
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir
GitHub PoC58
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
CVE-2019-1863407 feb 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC237
Proof of Concept for CVE-2019-18634
CVE-2019-1863407 feb 2020
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir
GitHub PoC
Adapted CVE-2015-8562 payload
CVE-2015-856207 feb 2020
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir
GitHub PoC1
Final Project for Security and Privacy CS 600.443
CVE-2011-486206 feb 2020
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir
GitHub PoC1
CVE-2019-5736 implemented in a self-written container runtime to understand the exploit.
CVE-2019-573604 feb 2020
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC5
CVE-2014-2630 exploit for xglance-bin
CVE-2014-263004 feb 2020
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RIESGO
abrir
GitHub PoC1
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall
CVE-2020-0601HIGHbajo ataque03 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC1
Resources related to CurveBall (CVE-2020-0601) detection
CVE-2020-0601HIGHbajo ataque03 feb 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC68
CVE-2019-8449 Exploit for Jira v2.1 - v8.3.4
CVE-2019-844902 feb 2020
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username
60RIESGO
abrir
GitHub PoC
A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.
CVE-2004-227102 feb 2020
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir
GitHub PoC25
Python exploit of cve-2020-7247
CVE-2020-7247CRITICALbajo ataque30 ene 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC26
Temproot for Bravia TV via CVE-2019-2215.
CVE-2019-2215HIGHbajo ataque30 ene 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
GitHub PoC
ianxtianxt/CVE-2016-8735
CVE-2016-8735CRITICALbajo ataque29 ene 2020
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8
100RIESGO
abrir
GitHub PoC4
TheCyberGeek/CVE-2020-5844
CVE-2020-584429 ene 2020
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RIESGO
abrir
GitHub PoC1
proof of concept for CVE-2020-0601
CVE-2020-0601HIGHbajo ataque29 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC1
*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :) --- somhmxxghoul ---
CVE-2014-6271CRITICALbajo ataque28 ene 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC20
PoC for CVE-2020-0601 - CryptoAPI exploit
CVE-2020-0601HIGHbajo ataque28 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC1
Python CVE-2019-19781 exploit
CVE-2019-19781CRITICALbajo ataqueransomware28 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC73
PoC script that shows RCE vulnerability over Intellian Satellite controller
CVE-2020-798028 ene 2020
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RIESGO
abrir
GitHub PoC41
This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)
CVE-2019-1125MEDIUM27 ene 2020
Windows Kernel Information Disclosure Vulnerability
33RIESGO
abrir
GitHub PoC
PoC for "CurveBall" CVE-2020-0601
CVE-2020-0601HIGHbajo ataque25 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC68
A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.
CVE-2020-060924 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RIESGO
abrir
GitHub PoC2
Archi73ct/CVE-2020-0609
CVE-2020-060924 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RIESGO
abrir
GitHub PoC
Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts
CVE-2019-19781CRITICALbajo ataqueransomware24 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC78
PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610
CVE-2020-060924 ene 2020
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated atta
45RIESGO
abrir
GitHub PoC1
CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)
CVE-2020-0601HIGHbajo ataque23 ene 2020
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) c
93RIESGO
abrir
GitHub PoC
:microscope: Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware23 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
GitHub PoC
a script to look for CVE-2019-19781 Vulnerability within a domain and it's subdomains
CVE-2019-19781CRITICALbajo ataqueransomware23 ene 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
anteriorpágina 407 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.