Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.607exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC5
Netis router RCE exploit ( CVE-2019-19356)
CVE-2019-19356HIGHbajo ataque12 dic 2019
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RIESGO
abrir
GitHub PoC3
Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.
CVE-2019-573612 dic 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC373
RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.
CVE-2019-18935CRITICALbajo ataqueransomware12 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC30
详解 k8gege的SharePoint RCE exploit cve-2019-0604-exp.py的代码,动手制作自己的payload
CVE-2019-0604CRITICALbajo ataqueransomware10 dic 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
GitHub PoC
CVE-2014-1322 - IPC Local Security Bypass | Mac OSX (Affected. >= 10.9.2)
CVE-2014-132210 dic 2019
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RIESGO
abrir
GitHub PoC1
FreePBX exploit <= 2.8.0
CVE-2010-349009 dic 2019
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RIESGO
abrir
GitHub PoC1
CVE-2008-1611 TFTP 1.41 buffer overflow exploit in the filepath
CVE-2008-161108 dic 2019
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RIESGO
abrir
GitHub PoC9
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
CVE-2019-11510CRITICALbajo ataqueransomware07 dic 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC109
CVE-2019-0708 (BlueKeep)
CVE-2019-0708CRITICALbajo ataqueransomware07 dic 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC3
AppXSvc Arbitrary File Overwrite DoS
CVE-2019-147605 dic 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RIESGO
abrir
GitHub PoC12
This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3
CVE-2019-1957604 dic 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RIESGO
abrir
GitHub PoC21
hekadan/CVE-2019-7609
CVE-2019-7609CRITICALbajo ataque01 dic 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC1
IE7 buffer overflow through an ANI file
CVE-2007-003829 nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir
GitHub PoC4
Exploit for CVE-2017-12945.
CVE-2017-1294527 nov 2019
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen
28RIESGO
abrir
GitHub PoC72
guest→system(UAC手动提权)
CVE-2019-1388HIGHbajo ataqueransomware27 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC6
Python script to exploit RCE in Nostromo nhttpd <= 1.9.6.
CVE-2019-16278CRITICALbajo ataque26 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
Exploit the dirtycow vulnerability to login as root
CVE-2016-5195HIGHbajo ataque26 nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC7
timwr/CVE-2019-5825
CVE-2019-5825MEDIUMbajo ataque23 nov 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC
crispy-peppers/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL23 nov 2019
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC
crispy-peppers/Goahead-CVE-2017-17562
CVE-2017-17562HIGHbajo ataque23 nov 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC8
A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Simply takes a host and port that the web server is running on.
CVE-2019-16278CRITICALbajo ataque22 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC1
ulisesrc/-2-CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware22 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
jaychouzzk/CVE-2019-1388
CVE-2019-1388HIGHbajo ataqueransomware21 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC193
CVE-2019-1388 UAC提权 (nt authority\system)
CVE-2019-1388HIGHbajo ataqueransomware21 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC
am6539/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware21 nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC20
CVE-2019-0232-Remote Code Execution on Apache Tomcat 7.0.42
CVE-2019-023221 nov 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC1
l-iberty/cve-2012-1889
CVE-2012-1889HIGHbajo ataque20 nov 2019
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir
GitHub PoC51
Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894
CVE-2020-0796CRITICALbajo ataqueransomware19 nov 2019
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC5
random-robbie/CVE-2019-5418
CVE-2019-5418HIGHbajo ataque19 nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC1
remote debug environment for CLion
CVE-2019-11043HIGHbajo ataqueransomware17 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
anteriorpágina 411 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.