Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.608exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
13.960 exploits
GitHub PoC
3rg1s/CVE-2016-2098
CVE-2016-209830 oct 2019
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC8
Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.
CVE-2019-11043HIGHbajo ataqueransomware30 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC10
Mayter/CVE-2019-1315
CVE-2019-1315HIGHbajo ataqueransomware29 oct 2019
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
71RIESGO
abrir
GitHub PoC5
Python exp for CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware29 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC146
(PoC) Python version of CVE-2019-11043 exploit by neex
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
huang919/cve-2019-14287-PPT
CVE-2019-1428728 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
CVE-2019-11043 PHP远程代码执行
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
TEST
CVE-2019-3396CRITICALbajo ataqueransomware28 oct 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC4
apache axis1.4远程代码执行漏洞
CVE-2019-022727 oct 2019
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RIESGO
abrir
GitHub PoC7
FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)
CVE-2019-1887327 oct 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RIESGO
abrir
GitHub PoC19
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2019-10149CRITICALbajo ataque27 oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC2
CVE-2000-0979
CVE-2000-097926 oct 2019
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RIESGO
abrir
GitHub PoC
CVE-2015-7547 initial research.
CVE-2015-754724 oct 2019
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC
melardev/CVE-2019-5418
CVE-2019-5418HIGHbajo ataque24 oct 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
GitHub PoC1
fairyming/CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware24 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC4
PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python
CVE-2019-11043HIGHbajo ataqueransomware24 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
ianxtianxt/CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware24 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC3
Remote Code Execution Vulnerability in Webmin
CVE-2019-15107CRITICALbajo ataqueransomware24 oct 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC27
akamajoris/CVE-2019-11043-Docker
CVE-2019-11043HIGHbajo ataqueransomware24 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC16
Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
CVE-2019-1193223 oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC
CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware23 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC105
php-fpm+Nginx RCE
CVE-2019-11043HIGHbajo ataqueransomware23 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
tinker-li/CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware23 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC1
CVE-2019-16278 Python3 Exploit Code
CVE-2019-16278CRITICALbajo ataque23 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC
leonardo1101/cve-2017-11176
CVE-2017-1117623 oct 2019
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
GitHub PoC
ictnamanh/CVE-2017-9248
CVE-2017-9248CRITICALbajo ataque23 oct 2019
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC9
脏牛Linux本地提权漏洞复现(CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque22 oct 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC167
exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts
CVE-2019-7609CRITICALbajo ataque21 oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC56
RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer
CVE-2019-7609CRITICALbajo ataque21 oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC5
Instructions for installing a vulnerable version of Exim and its expluatation
CVE-2019-10149CRITICALbajo ataque21 oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
anteriorpágina 413 / 466siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.